Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · emerson

emerson

· 9 Critical

Total CVEs

85

Critical

9

Products

151

Search All CVEs →

85

Products (151)

deltav15 CVEswireless 1420 gateway8 CVEswireless 1420 gateway firmware8 CVEsx-stream enhanced xegp7 CVEswireless 1410 gateway7 CVEsx-stream enhanced xegp firmware7 CVEswireless 1410 gateway firmware7 CVEsx-stream enhanced xexf7 CVEsx-stream enhanced xegk firmware7 CVEsx-stream enhanced xegk7 CVEsx-stream enhanced xexf firmware7 CVEsx-stream enhanced xefd firmware7 CVEsx-stream enhanced xefd7 CVEsse4801t0x redundant wireless i\/o card firmware6 CVEsse4801t0x redundant wireless i\/o card6 CVEsdeltav workstation6 CVEswireless 1410d gateway firmware6 CVEswireless 1410d gateway6 CVEsdl 8000 remote terminal unit5 CVEselectric\'s proficy5 CVEsdeltav distributed control system sq controller5 CVEsdeltav distributed control system sq controller firmware5 CVEsdeltav distributed control system sx controller5 CVEsopenenterprise scada server5 CVEsdeltav distributed control system sx controller firmware5 CVEsdeltav proessentials scientific graph5 CVEsse4037p0 h1 i\/o interface card and terminl block5 CVEsse4002s1t2b6 high side 40-pin mass i\/o terminal block firmware5 CVEsse4003s2b4 16-pin mass i\/o terminal block5 CVEsse4003s2b4 16-pin mass i\/o terminal block firmware5 CVEsse4003s2b524-pin mass i\/o terminal block5 CVEsse4003s2b524-pin mass i\/o terminal block firmware5 CVEsse4017p0 h1 i\/o interface card and terminl block5 CVEsse4017p0 h1 i\/o interface card and terminl block firmware5 CVEsse4017p1 h1 i\/o card with integrated power5 CVEsse4017p1 h1 i\/o card with integrated power firmware5 CVEsse4019p0 simplex h1 4-port plus fieldbus i\/o interface with terminalblock5 CVEsse4019p0 simplex h1 4-port plus fieldbus i\/o interface with terminalblock firmware5 CVEsse4026 virtual i\/o module 25 CVEsse4026 virtual i\/o module 2 firmware5 CVEsse4027 virtual i\/o module 25 CVEsse4027 virtual i\/o module 2 firmware5 CVEsse4032s1t2b8 high side 40-pin do mass i\/o terminal block5 CVEsse4032s1t2b8 high side 40-pin do mass i\/o terminal block firmware5 CVEsse4052s1t2b6 high side 40-pin mass i\/o terminal block firmware5 CVEsse4052s1t2b6 high side 40-pin mass i\/o terminal block5 CVEsse4039p0 redundant h1 4-port plus fieldbus i\/o interface with terminalblock firmware5 CVEsse4039p0 redundant h1 4-port plus fieldbus i\/o interface with terminalblock5 CVEsse4037p1 redundant h1 i\/o card with integrated power and terminal block firmware5 CVEsse4037p1 redundant h1 i\/o card with integrated power and terminal block5 CVEsse4037p0 h1 i\/o interface card and terminl block firmware5 CVEsse4002s1t2b6 high side 40-pin mass i\/o terminal block5 CVEsve4107 iec 61850 mms interface for ethernet connected i\/o \(eioc\) firmware5 CVEsve4107 iec 61850 mms interface for ethernet connected i\/o \(eioc\)5 CVEsve4106 opc-ua client for ethernet connected i\/o \(eioc\) firmware5 CVEsve4106 opc-ua client for ethernet connected i\/o \(eioc\)5 CVEsve4105 ethernet\/ip interface for ethernet connected i\/o \(eioc\) firmware5 CVEsroc 800 remote terminal unit5 CVEsve4105 ethernet\/ip interface for ethernet connected i\/o \(eioc\)5 CVEsroc 800l remote terminal unit5 CVEsve4104 ethernet\/ip control tag integration for ethernet connected i\/o \(eioc\) firmware5 CVEsve4104 ethernet\/ip control tag integration for ethernet connected i\/o \(eioc\)5 CVEsve4103 modbus tcp interface for ethernet connected i\/o \(eioc\) firmware5 CVEsve4103 modbus tcp interface for ethernet connected i\/o \(eioc\)5 CVEsse4101 simplex ethernet i\/o card \(eioc\) assembly firmware5 CVEsse4101 simplex ethernet i\/o card \(eioc\) assembly5 CVEsse4100 simplex ethernet i\/o card \(eioc\) assembly firmware5 CVEsse4100 simplex ethernet i\/o card \(eioc\) assembly5 CVEsse4082s1t2b8 high side 40-pin do mass i\/o terminal block firmware5 CVEsse4082s1t2b8 high side 40-pin do mass i\/o terminal block5 CVEsgc1500xa firmware4 CVEsgc700xa4 CVEsgc1500xa4 CVEsgc370xa firmware4 CVEsgc370xa4 CVEsgc700xa firmware4 CVEsdeltav distributed control system3 CVEsams device manager3 CVEsdixell xweb-500 firmware2 CVEscontrolwave micro2 CVEscontrolwave micro firmware2 CVEsdata record ad2 CVEsdixell xweb-5002 CVEsdl80002 CVEsdl8000 firmware2 CVEsflexlogger2 CVEsg web development software2 CVEslabview nxg2 CVEsopenbsi2 CVEsovation ocr4002 CVEsovation ocr400 firmware2 CVEsproficy machine edition2 CVEsroc8092 CVEsroc809 firmware2 CVEsroc8272 CVEsroc827 firmware2 CVEsspecification compliance manager2 CVEsstatic test software suite2 CVEssts software bundle2 CVEssystemlink server2 CVEsrx3i cpe400 firmware1 CVEsrx3i cpe4001 CVEsrx3i cpe330 firmware1 CVEsrx3i cpe3301 CVEsrx3i cpe310 firmware1 CVEsrx3i cpe3101 CVEsrx3i cpe305 firmware1 CVEsrx3i cpe3051 CVEsrx3i cpe302 firmware1 CVEsrx3i cpe3021 CVEsrx3i cpe115 firmware1 CVEsrx3i cpe1151 CVEsse4801t1x simplex wireless i\/o card1 CVEsse4801t1x simplex wireless i\/o card firmware1 CVEssmart wireless gateway 14201 CVEssmart wireless gateway 1420 firmware1 CVEscontrolwave pac firmware1 CVEscontrolwave pac1 CVEsxweb300d evo1 CVEsxweb300d evo firmware1 CVEsvalvelink1 CVEsrx3i cpe100 firmware1 CVEsrx3i cpe1001 CVEsrosemount transmitter interface software1 CVEsroc 800l remote terminal unit firmware1 CVEsroc 800 remote terminal unit firmware1 CVEsroc827l firmware1 CVEsroc827l1 CVEsroc809l firmware1 CVEsroc809l1 CVEsroc800l firmware1 CVEsve60461 CVEsve6046 firmware1 CVEsroc800l1 CVEsproficy1 CVEsnetwork power avocent mergepoint unity 2016 firmware1 CVEsliebert sitescan web1 CVEsliebert challenger firmware1 CVEsliebert challenger1 CVEswireless 1552wu gateway1 CVEswireless 1552wu gateway firmware1 CVEsfb3000 rtu firmware1 CVEsfb3000 rtu1 CVEsdl 8000 remote terminal unit firmware1 CVEsdeltav ve3006 controller md plus1 CVEsdeltav ve3005 controller md1 CVEsdeltav se3006 sd plus controller1 CVEsrx3i cru320 firmware1 CVEsrx3i cru3201 CVEsrx3i cpl410 firmware1 CVEsrx3i cpl4101 CVEs

Recent Vulnerabilities

View all 85
CVE-2024-1156HIGH 7.8

Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges.

CVE-2024-1155HIGH 7.8

Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-51761HIGH 8.3

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire admin capabilities.

CVE-2023-49716MEDIUM 6.9

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote computer.

CVE-2023-46687CRITICAL 9.8

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could execute arbitrary commands in root context from a remote computer.

CVE-2023-43609MEDIUM 6.9

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain access to sensitive information or cause a denial-of-service condition.

CVE-2023-1935CRITICAL 9.4

ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized access to data or control of the device and cause a denial-of-service condition.

CVE-2022-30260HIGH 7.8

Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC IO cards.

CVE-2022-2791MEDIUM 5.9

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File with Dangerous Type, and will upload any file written into the PLC logic folder to the connected PLC.

CVE-2022-2793MEDIUM 5.9

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no authentication or authorization of data packets after establishing a connection for the SRTP protocol.

CVE-2022-2792MEDIUM 6.6

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and stores project data in a directory with improper access control lists.

CVE-2022-2790MEDIUM 5.9

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryptographic Signature, and does not properly verify compiled logic (PDT files) and data blocks data (BLD/BLK files).

CVE-2022-2789MEDIUM 4.7

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of Data Authenticity, and can display logic that is different than the compiled logic.

CVE-2022-2788LOW 3.9

Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip attack, through an upload procedure which enables attackers to implant a malicious .BLZ file on the PLC. The file can transfer through the engineering station onto Windows in a way that executes the malicious code.

CVE-2022-30262HIGH 7.8

The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP protocol to transmit firmware updates. Firmware updates are supplied as CAB archive files containing a binary firmware image. In all cases, firmware images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.

CVE-2022-30264CRITICAL 9.8

The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications between a master terminal and RTUs. Opcode 203 of this protocol allows a master terminal to transfer files to and from the flash filesystem and carrying out arbitrary file and directory read, write, and delete operations.

CVE-2022-29959MEDIUM 5.5

Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. This environment provides access control functionality through user authentication and privilege management. The credentials for various users are stored insecurely in the SecUsers.ini file by using a simple string transformation rather than a cryptographic mechanism.

CVE-2022-29965MEDIUM 5.5

The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on the maintenance port TELNET interface (23/TCP) on M-series and SIS (CSLS/LSNB/LSNG) nodes is controlled by means of utility passwords. These passwords are generated using a deterministic, insecure algorithm using a single seed value composed of a day/hour/minute timestamp with less than 16 bits of entropy. The seed value is fed through a lookup table and a series of permutation operations resulting in three different four-character passwords corresponding to different privilege levels. An attacker can easily reconstruct these passwords and thus gain access to privileged maintenance operations. NOTE: this is different from CVE-2014-2350.

CVE-2022-29964MEDIUM 5.5

The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell as root, DeltaV, or backup via hardcoded credentials. NOTE: this is different from CVE-2014-2350.

CVE-2022-29963MEDIUM 5.5

The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides access to a root shell via hardcoded credentials. This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350.

CVE-2022-29962MEDIUM 5.5

The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350.

CVE-2022-29960MEDIUM 5.5

Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES with hardcoded cryptographic keys is used for protection of certain system credentials, engineering files, and sensitive utilities.

CVE-2022-29957HIGH 7.8

The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wide variety of functionality. These protocols include Firmware upgrade (18508/TCP, 18518/TCP); Plug-and-Play (18510/UDP); Hawk services (18507/UDP); Management (18519/TCP); Cold restart (18512/UDP); SIS communications (12345/TCP); and Wireless Gateway Protocol (18515/UDP). None of these protocols have any authentication features, allowing any attacker capable of communicating with the ports in question to invoke (a subset of) desired functionality.

CVE-2020-16235LOW 3.8

Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through version 3.3.5, to access field devices and external systems to be obtained.

CVE-2020-10640CRITICAL 10.0

Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service.