CVE-2022-29960

MEDIUM

Emerson OpenBSI through 2022-04-29 - Use of Hard-coded Credentials via DES Encryption

Title source: llm
STIX 2.1

Description

Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES with hardcoded cryptographic keys is used for protection of certain system credentials, engineering files, and sensitive utilities.

References (3)

Core 3
Core References
Third Party Advisory x_refsource_misc
https://www.forescout.com/blog/
Not Applicable, Third Party Advisory, US Government Resource x_refsource_misc
https://www.cisa.gov/uscert/ics/advisories/icsa-22-181-03
Third Party Advisory, US Government Resource x_refsource_misc
https://www.cisa.gov/uscert/ics/advisories/icsa-22-221-03

Scores

CVSS v3 5.5
EPSS 0.0043
EPSS Percentile 33.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-798
Status published
Products (2)
emerson/openbsi 5.9 (4 CPE variants)
emerson/openbsi < 5.9
Published Jul 26, 2022
Tracked Since Feb 18, 2026