Vulnerabilities > Emerson > Electric S Proficy

DATE CVE VULNERABILITY TITLE RISK
2022-08-19 CVE-2022-2792 Unspecified vulnerability in Emerson Electric'S Proficy
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and stores project data in a directory with improper access control lists.
network
low complexity
emerson
7.5
2022-08-19 CVE-2022-2788 Path Traversal vulnerability in Emerson Electric'S Proficy
Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip attack, through an upload procedure which enables attackers to implant a malicious .BLZ file on the PLC.
local
low complexity
emerson CWE-22
7.3