PT-2020-2740 · Emerson · Emerson Openenterprise
Roman Lozko
·
Published
2020-05-20
·
Updated
2022-03-04
·
CVE-2020-10640
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Emerson OpenEnterprise versions through 3.3.4
Description
The issue is related to the incorrect implementation of the authentication mechanism in the Emerson OpenEnterprise SCADA platform for remote oil and gas applications. This may allow an attacker to execute arbitrary commands with system privileges or perform remote code execution via a specific communication service by sending a specially crafted malicious service message.
Recommendations
For Emerson OpenEnterprise versions through 3.3.4, consider disabling the specific communication service that allows remote code execution until a patch is available. Restrict access to the system to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emerson Openenterprise