Vulnerabilities > Enea

DATE CVE VULNERABILITY TITLE RISK
2013-10-03 CVE-2013-0694 Credentials Management vulnerability in multiple products
The Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier have hardcoded credentials in a ROM, which makes it easier for remote attackers to obtain shell access to the underlying OS by leveraging knowledge of the ROM contents from a product installation elsewhere.
network
low complexity
enea emerson CWE-255
critical
9.0
2013-10-03 CVE-2013-0693 Information Exposure vulnerability in multiple products
The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier performs network-beacon broadcasts, which allows remote attackers to obtain potentially sensitive information about device presence by listening for broadcast traffic.
network
low complexity
enea emerson CWE-200
critical
10.0
2013-10-03 CVE-2013-0692 Permissions, Privileges, and Access Controls vulnerability in multiple products
The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to execute arbitrary code by connecting to the debug service.
network
low complexity
enea emerson CWE-264
critical
10.0
2013-10-03 CVE-2013-0689 Code Injection vulnerability in multiple products
The TFTP server on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to upload files and consequently execute arbitrary code via unspecified vectors.
network
low complexity
enea emerson CWE-94
critical
10.0