7.8

CVE-2022-30262

The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP protocol to transmit firmware updates. Firmware updates are supplied as CAB archive files containing a binary firmware image. In all cases, firmware images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Emerson ≫ Controlwave Pac Firmware Version <= 2022-05-02
   Emerson ≫ Controlwave Pac Version -
Emerson ≫ Controlwave Micro Firmware Version <= 2022-05-02
   Emerson ≫ Controlwave Micro Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.076
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-345 Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

https://www.forescout.com/blog/
Third Party Advisory
https://www.cisa.gov/uscert/ics/advisories/icsa-22-221-02
Third Party Advisory
US Government Resource
Mitigation