CVE-2022-30262
HIGHEmerson ControlWave PAC and Micro Firmware < 2022-05-02 - Insufficient Firmware Integrity Verification
Title source: llmDescription
The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP protocol to transmit firmware updates. Firmware updates are supplied as CAB archive files containing a binary firmware image. In all cases, firmware images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://www.forescout.com/blog/
Mitigation, Third Party Advisory, US Government Resource x_refsource_misc
https://www.cisa.gov/uscert/ics/advisories/icsa-22-221-02
Scores
CVSS v3
7.8
EPSS
0.0015
EPSS Percentile
4.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-345
Status
published
Products (2)
emerson/controlwave_micro_firmware
< 2022-05-02
emerson/controlwave_pac_firmware
< 2022-05-02
Published
Aug 17, 2022
Tracked Since
Feb 18, 2026