PT-2022-3162 · Emerson · Emerson Openbsi

Daniel Dos Santos

+1

·

Published

2022-06-22

·

Updated

2024-02-13

·

CVE-2022-29960

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Emerson OpenBSI through 2022-04-29
Description The issue is related to the use of weak cryptography in Emerson OpenBSI, an engineering environment for the ControlWave and Bristol Babcock line of RTUs. Specifically, DES with hardcoded cryptographic keys is used for protecting certain system credentials, engineering files, and sensitive utilities. This could allow a remote attacker to gain access to credentials.
Recommendations For Emerson OpenBSI through 2022-04-29, consider disabling the use of DES with hardcoded cryptographic keys as a temporary workaround until a patch is available. Restrict access to sensitive utilities and engineering files to minimize the risk of exploitation. Update to a version that uses secure cryptography for protecting system credentials and sensitive data.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2022-03842
CVE-2022-29960

Affected Products

Emerson Openbsi