PT-2022-3158 · Emerson · Emerson Openbsi

Daniel Dos Santos

+1

·

Published

2022-06-22

·

Updated

2024-02-13

·

CVE-2022-29959

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Emerson OpenBSI versions prior to 2022-04-29
Description The issue is related to the insecure storage of confidential information in the SecUsers.ini file, which can be exploited by a remote attacker to gain access to user credentials. The Emerson OpenBSI environment, used for the ControlWave and Bristol Babcock line of RTUs, provides access control functionality through user authentication and privilege management. However, the credentials for various users are stored insecurely using a simple string transformation rather than a cryptographic mechanism.
Recommendations For Emerson OpenBSI versions prior to 2022-04-29, consider updating to a version that securely stores user credentials using a cryptographic mechanism. As a temporary workaround, restrict access to the SecUsers.ini file to minimize the risk of exploitation. Additionally, review and implement best practices for secure credential storage to prevent similar issues in the future.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2022-03838
CVE-2022-29959

Affected Products

Emerson Openbsi