CVE-2014-2349

Emerson DeltaV 10.3.1 11.3 11.3.1 12.3 - Unauthenticated Hardcoded Credential Bypass via TCP Session

Title source: llm
STIX 2.1

Description

Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that uses the telnet program.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource
http://ics-cert.us-cert.gov/advisories/ICSA-14-133-02
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-14-133-02

Scores

EPSS 0.0066
EPSS Percentile 46.5%

Details

CWE
CWE-264 CWE-285
Status published
Products (8)
emerson/deltav 10.3.1
emerson/deltav 11.3
emerson/deltav 11.3.1
emerson/deltav 12.3
Emerson/DeltaV 10.3.1
Emerson/DeltaV 11.3
Emerson/DeltaV 11.3.1
Emerson/DeltaV 12.3
Published May 22, 2014
Tracked Since Feb 18, 2026