Release date:
Updated on:
Affected Systems:
Emersonprocess DeltaV Workstations 9
Emersonprocess DeltaV Workstations 11
Emersonprocess DeltaV Workstations 10
Emersonprocess DeltaV proessential tials Scientific Graph
Emersonprocess DeltaV 10
Emersonprocess DeltaV 9
Emersonprocess DeltaV 11
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53591
Cve id: CVE-2012-1814, CVE-2012-1815, CVE-2012-1816, CVE-2012-1817, CVE-2012-1818
DeltaV is the Process Management System Department of Emerson that provides process management solutions for different scales, as well as powerful and easy-to-use process control and equipment management, a process control system with a new structure and a digital automatic system.
Multiple DeltaV products have multiple remote vulnerabilities. These vulnerabilities allow attackers to steal Cookie authentication creden。, access or modify data, execute arbitrary code, and reject services.
<* Source: Kuang-Chun Hung
Link: http://www.us-cert.gov/control_systems/pdf/ICSA-12-138-01.pdf
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Emersonprocess
--------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www2.emersonprocess.com/en-US/brands/DeltaV/Pages/index.aspx