CVE-2022-29959
MEDIUMEmerson Openbsi < 5.9 - Insufficiently Protected Credentials
Title source: ruleDescription
Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. This environment provides access control functionality through user authentication and privilege management. The credentials for various users are stored insecurely in the SecUsers.ini file by using a simple string transformation rather than a cryptographic mechanism.
Scores
CVSS v3
5.5
EPSS
0.0010
EPSS Percentile
28.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-522
Status
published
Affected Products (5)
emerson/openbsi
< 5.9
emerson/openbsi
emerson/openbsi
emerson/openbsi
emerson/openbsi
Timeline
Published
Aug 16, 2022
Tracked Since
Feb 18, 2026