PT-2022-18697 · Emerson Electric · Proficy Machine Edition
Sharon Brizinov
·
Published
2022-08-19
·
Updated
2022-08-24
·
CVE-2022-2793
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Emerson Electric's Proficy Machine Edition versions 9.00 and prior
Description
The issue concerns a lack of integrity check support, allowing for potential data manipulation. Specifically, after establishing a connection using the SRTP protocol, there is no authentication or authorization of data packets.
Recommendations
For versions 9.00 and prior, consider implementing additional integrity check mechanisms to ensure the authenticity of data packets after a connection is established. As a temporary workaround, restrict access to the SRTP protocol to minimize the risk of exploitation.
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Proficy Machine Edition