CVE-2021-44463

HIGH

Emerson DeltaV - Uncontrolled Search Path Element

Title source: llm
STIX 2.1

Description

Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations (All versions) when some DeltaV services are started.

References (1)

Core 1
Core References
Mitigation, Third Party Advisory, US Government Resource x_refsource_misc
https://www.cisa.gov/uscert/ics/advisories/icsa-21-355-04

Scores

CVSS v3 8.1
EPSS 0.0026
EPSS Percentile 17.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-427
Status published
Products (4)
emerson/deltav 13.3.1
emerson/deltav 14 feature_pack1 (2 CPE variants)
emerson/deltav 14.3.1
emerson/deltav r6
Published Jan 28, 2022
Tracked Since Feb 18, 2026