CVE-2018-14795

HIGH

Emerson DeltaV 11.3.1 12.3.1 13.3.0 13.3.1 R5 - Path Traversal

Title source: llm
STIX 2.1

Description

DeltaV Versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, and R5 is vulnerable due to improper path validation which may allow an attacker to replace executable files.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-18-228-01
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105105

Scores

CVSS v3 8.8
EPSS 0.0219
EPSS Percentile 80.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22 CWE-23
Status published
Products (5)
emerson/deltav 11.3.1
emerson/deltav 12.3.1
emerson/deltav 13.3.0
emerson/deltav 13.3.1
emerson/deltav r5
Published Aug 21, 2018
Tracked Since Feb 18, 2026