8.1

CVE-2023-51761

Emerson Rosemount GC370XA, GC700XA, GC1500XA Improper Authentication

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire admin capabilities.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Emerson ≫ Gc370xa Firmware Version 4.1.5
   Emerson ≫ Gc370xa Version -
Emerson ≫ Gc700xa Firmware Version 4.1.5
   Emerson ≫ Gc700xa Version -
Emerson ≫ Gc1500xa Firmware Version 4.1.5
   Emerson ≫ Gc1500xa Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.68% 0.476
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
DHS.gov 8.3 1.6 6
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://www.cisa.gov/news-events/ics-advisories/icsa-24-030-01
Third Party Advisory
US Government Resource
https://www.emerson.com/documents/automation/security-notification-emerson-gas-chromatographs-cyber-security-notification-icsa-24-030-01-en-10103910.pdf
Vendor Advisory