Emerson Vulnerabilities and Affected Products
Vulnerabilities associated with ValveLink SOLO.
Products
Clear product- WirelessHART Gateway6 vulnerabilities
- ValveLink DTM5 vulnerabilities
- ValveLink PRM5 vulnerabilities
- ValveLink SNAP-ON5 vulnerabilities
- ValveLink SOLO5 vulnerabilities
- Rosemount GC1500XA4 vulnerabilities
- Rosemount GC370XA4 vulnerabilities
- Rosemount GC700XA4 vulnerabilities
- OpenEnterprise SCADA Software3 vulnerabilities
- AMS Device Manager2 vulnerabilities
- DeltaV2 vulnerabilities
- DeltaV DCS2 vulnerabilities
- Emerson Ovation OCR400 Controller2 vulnerabilities
- dixell_xweb-500_firmware1 vulnerability
- Emerson DeltaV1 vulnerability
- Emerson PAC Machine Edition1 vulnerability
- Open Enterprise1 vulnerability
- OpenEnterprise1 vulnerability
- OpenEnterprise SCADA Server1 vulnerability
- Wireless 1410 Gateway1 vulnerability
- Wireless 1420 Gateway1 vulnerability
- Wireless 1552WU Gateway1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-53471MEDIUM | Emerson ValveLink Products Improper Input ValidationEmerson ValveLink products receive input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. CWE-20Jul 10, 2025 | CVSS5.9v4.0 | EPSS0.164% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-48496MEDIUM | Emerson ValveLink Products Uncontrolled Search Path ElementEmerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors. CWE-427Jul 10, 2025 | CVSS5.9v4.0 | EPSS0.168% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-46358HIGH | Emerson ValveLink Products Protection Mechanism FailureEmerson ValveLink products do not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product. CWE-693Jul 10, 2025 | CVSS8.5v4.0 | EPSS0.173% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-50109HIGH | Emerson ValveLink Products Cleartext Storage of Sensitive Information in MemoryEmerson ValveLink Products store sensitive information in cleartext within a resource that might be accessible to another control sphere. CWE-316Jul 10, 2025 | CVSS8.5v4.0 | EPSS0.122% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-52579CRITICAL | Emerson ValveLink Products Cleartext Storage of Sensitive Information in MemoryEmerson ValveLink Products store sensitive information in cleartext in memory. The sensitive memory might be saved to disk, stored in a core dump, or remain uncleared if the product crashes, or if the programmer does not properly clear the memory before freeing it. CWE-316Jul 10, 2025 | CVSS9.3v4.0 | EPSS0.372% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |