PT-2022-18697 · Emerson Electric · Proficy Machine Edition

Sharon Brizinov

·

Published

2022-08-19

·

Updated

2022-08-24

·

CVE-2022-2793

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Emerson Electric's Proficy Machine Edition versions 9.00 and prior
Description The issue concerns a lack of integrity check support, allowing for potential data manipulation. Specifically, after establishing a connection using the SRTP protocol, there is no authentication or authorization of data packets.
Recommendations For versions 9.00 and prior, consider implementing additional integrity check mechanisms to ensure the authenticity of data packets after a connection is established. As a temporary workaround, restrict access to the SRTP protocol to minimize the risk of exploitation.

Fix

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

CVE-2022-2793

Affected Products

Proficy Machine Edition