PT-2022-3162 · Emerson · Emerson Openbsi
Daniel Dos Santos
+1
·
Published
2022-06-22
·
Updated
2024-02-13
·
CVE-2022-29960
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Emerson OpenBSI through 2022-04-29
Description
The issue is related to the use of weak cryptography in Emerson OpenBSI, an engineering environment for the ControlWave and Bristol Babcock line of RTUs. Specifically, DES with hardcoded cryptographic keys is used for protecting certain system credentials, engineering files, and sensitive utilities. This could allow a remote attacker to gain access to credentials.
Recommendations
For Emerson OpenBSI through 2022-04-29, consider disabling the use of DES with hardcoded cryptographic keys as a temporary workaround until a patch is available. Restrict access to sensitive utilities and engineering files to minimize the risk of exploitation. Update to a version that uses secure cryptography for protecting system credentials and sensitive data.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emerson Openbsi