PT-2021-7809 · Emerson · Emerson Ge Automation Proficy Machine Edition

Published

2021-07-30

·

Updated

2021-08-09

·

CVE-2021-29298

CVSS v2.0

5.4

Medium

VectorAV:N/AC:H/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Emerson GE Automation Proficy Machine Edition version 8.0
Description The issue is related to improper input validation in the component "FrameworX.exe" within the module "fxVPStatcTcp.dll". This can be exploited by an attacker via a Man-in-the-Middle (MITM) attack using crafted traffic, potentially leading to a denial of service and application crash. The vulnerability is associated with insufficient input data validation when processing the dynamic library fxVPStatcTcp.dll, which could allow a remote attacker to cause a denial of service.
Recommendations For Emerson GE Automation Proficy Machine Edition version 8.0, consider disabling the "FrameworX.exe" component or restricting access to the "fxVPStatcTcp.dll" module as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03015
CVE-2021-29298

Affected Products

Emerson Ge Automation Proficy Machine Edition