CVE-2022-30260
 
Severity Score
7.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC IO cards.
Emerson DeltaV Distributed Control System (DCS) tiene una verificación insuficiente de la integridad del firmware (un método de suma de verificación inadecuado y sin firma). Esto afecta a las versiones anteriores a la 14.3 de las tarjetas DeltaV serie M, DeltaV serie S, DeltaV serie P, DeltaV SIS y DeltaV CIOC/EIOC/WIOC IO.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-05-04 CVE Reserved
- 2022-12-26 CVE Published
- 2024-07-18 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-345: Insufficient Verification of Data Authenticity
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-181-03 | Third Party Advisory | |
https://www.forescout.com/blog | Not Applicable |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Emerson Search vendor "Emerson" | Deltav Distributed Control System Sq Controller Firmware Search vendor "Emerson" for product "Deltav Distributed Control System Sq Controller Firmware" | < 14.3 Search vendor "Emerson" for product "Deltav Distributed Control System Sq Controller Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Deltav Distributed Control System Sq Controller Search vendor "Emerson" for product "Deltav Distributed Control System Sq Controller" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Deltav Distributed Control System Sx Controller Firmware Search vendor "Emerson" for product "Deltav Distributed Control System Sx Controller Firmware" | < 14.3 Search vendor "Emerson" for product "Deltav Distributed Control System Sx Controller Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Deltav Distributed Control System Sx Controller Search vendor "Emerson" for product "Deltav Distributed Control System Sx Controller" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Se4002s1t2b6 High Side 40-pin Mass I\/o Terminal Block Firmware Search vendor "Emerson" for product "Se4002s1t2b6 High Side 40-pin Mass I\/o Terminal Block Firmware" | < 14.3 Search vendor "Emerson" for product "Se4002s1t2b6 High Side 40-pin Mass I\/o Terminal Block Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Se4002s1t2b6 High Side 40-pin Mass I\/o Terminal Block Search vendor "Emerson" for product "Se4002s1t2b6 High Side 40-pin Mass I\/o Terminal Block" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Se4003s2b4 16-pin Mass I\/o Terminal Block Firmware Search vendor "Emerson" for product "Se4003s2b4 16-pin Mass I\/o Terminal Block Firmware" | < 14.3 Search vendor "Emerson" for product "Se4003s2b4 16-pin Mass I\/o Terminal Block Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Se4003s2b4 16-pin Mass I\/o Terminal Block Search vendor "Emerson" for product "Se4003s2b4 16-pin Mass I\/o Terminal Block" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Se4003s2b524-pin Mass I\/o Terminal Block Firmware Search vendor "Emerson" for product "Se4003s2b524-pin Mass I\/o Terminal Block Firmware" | < 14.3 Search vendor "Emerson" for product "Se4003s2b524-pin Mass I\/o Terminal Block Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Se4003s2b524-pin Mass I\/o Terminal Block Search vendor "Emerson" for product "Se4003s2b524-pin Mass I\/o Terminal Block" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Se4017p0 H1 I\/o Interface Card And Terminl Block Firmware Search vendor "Emerson" for product "Se4017p0 H1 I\/o Interface Card And Terminl Block Firmware" | < 14.3 Search vendor "Emerson" for product "Se4017p0 H1 I\/o Interface Card And Terminl Block Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Se4017p0 H1 I\/o Interface Card And Terminl Block Search vendor "Emerson" for product "Se4017p0 H1 I\/o Interface Card And Terminl Block" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Se4017p1 H1 I\/o Card With Integrated Power Firmware Search vendor "Emerson" for product "Se4017p1 H1 I\/o Card With Integrated Power Firmware" | < 14.3 Search vendor "Emerson" for product "Se4017p1 H1 I\/o Card With Integrated Power Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Se4017p1 H1 I\/o Card With Integrated Power Search vendor "Emerson" for product "Se4017p1 H1 I\/o Card With Integrated Power" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Se4019p0 Simplex H1 4-port Plus Fieldbus I\/o Interface With Terminalblock Firmware Search vendor "Emerson" for product "Se4019p0 Simplex H1 4-port Plus Fieldbus I\/o Interface With Terminalblock Firmware" | < 14.3 Search vendor "Emerson" for product "Se4019p0 Simplex H1 4-port Plus Fieldbus I\/o Interface With Terminalblock Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Se4019p0 Simplex H1 4-port Plus Fieldbus I\/o Interface With Terminalblock Search vendor "Emerson" for product "Se4019p0 Simplex H1 4-port Plus Fieldbus I\/o Interface With Terminalblock" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Se4026 Virtual I\/o Module 2 Firmware Search vendor "Emerson" for product "Se4026 Virtual I\/o Module 2 Firmware" | < 14.3 Search vendor "Emerson" for product "Se4026 Virtual I\/o Module 2 Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Se4026 Virtual I\/o Module 2 Search vendor "Emerson" for product "Se4026 Virtual I\/o Module 2" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Se4027 Virtual I\/o Module 2 Firmware Search vendor "Emerson" for product "Se4027 Virtual I\/o Module 2 Firmware" | < 14.3 Search vendor "Emerson" for product "Se4027 Virtual I\/o Module 2 Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Se4027 Virtual I\/o Module 2 Search vendor "Emerson" for product "Se4027 Virtual I\/o Module 2" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Se4032s1t2b8 High Side 40-pin Do Mass I\/o Terminal Block Firmware Search vendor "Emerson" for product "Se4032s1t2b8 High Side 40-pin Do Mass I\/o Terminal Block Firmware" | < 14.3 Search vendor "Emerson" for product "Se4032s1t2b8 High Side 40-pin Do Mass I\/o Terminal Block Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Se4032s1t2b8 High Side 40-pin Do Mass I\/o Terminal Block Search vendor "Emerson" for product "Se4032s1t2b8 High Side 40-pin Do Mass I\/o Terminal Block" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Se4037p0 H1 I\/o Interface Card And Terminl Block Firmware Search vendor "Emerson" for product "Se4037p0 H1 I\/o Interface Card And Terminl Block Firmware" | < 14.3 Search vendor "Emerson" for product "Se4037p0 H1 I\/o Interface Card And Terminl Block Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Se4037p0 H1 I\/o Interface Card And Terminl Block Search vendor "Emerson" for product "Se4037p0 H1 I\/o Interface Card And Terminl Block" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Se4037p1 Redundant H1 I\/o Card With Integrated Power And Terminal Block Firmware Search vendor "Emerson" for product "Se4037p1 Redundant H1 I\/o Card With Integrated Power And Terminal Block Firmware" | < 14.3 Search vendor "Emerson" for product "Se4037p1 Redundant H1 I\/o Card With Integrated Power And Terminal Block Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Se4037p1 Redundant H1 I\/o Card With Integrated Power And Terminal Block Search vendor "Emerson" for product "Se4037p1 Redundant H1 I\/o Card With Integrated Power And Terminal Block" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Se4039p0 Redundant H1 4-port Plus Fieldbus I\/o Interface With Terminalblock Firmware Search vendor "Emerson" for product "Se4039p0 Redundant H1 4-port Plus Fieldbus I\/o Interface With Terminalblock Firmware" | < 14.3 Search vendor "Emerson" for product "Se4039p0 Redundant H1 4-port Plus Fieldbus I\/o Interface With Terminalblock Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Se4039p0 Redundant H1 4-port Plus Fieldbus I\/o Interface With Terminalblock Search vendor "Emerson" for product "Se4039p0 Redundant H1 4-port Plus Fieldbus I\/o Interface With Terminalblock" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Se4052s1t2b6 High Side 40-pin Mass I\/o Terminal Block Firmware Search vendor "Emerson" for product "Se4052s1t2b6 High Side 40-pin Mass I\/o Terminal Block Firmware" | < 14.3 Search vendor "Emerson" for product "Se4052s1t2b6 High Side 40-pin Mass I\/o Terminal Block Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Se4052s1t2b6 High Side 40-pin Mass I\/o Terminal Block Search vendor "Emerson" for product "Se4052s1t2b6 High Side 40-pin Mass I\/o Terminal Block" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Se4082s1t2b8 High Side 40-pin Do Mass I\/o Terminal Block Firmware Search vendor "Emerson" for product "Se4082s1t2b8 High Side 40-pin Do Mass I\/o Terminal Block Firmware" | < 14.3 Search vendor "Emerson" for product "Se4082s1t2b8 High Side 40-pin Do Mass I\/o Terminal Block Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Se4082s1t2b8 High Side 40-pin Do Mass I\/o Terminal Block Search vendor "Emerson" for product "Se4082s1t2b8 High Side 40-pin Do Mass I\/o Terminal Block" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Se4100 Simplex Ethernet I\/o Card \(eioc\) Assembly Firmware Search vendor "Emerson" for product "Se4100 Simplex Ethernet I\/o Card \(eioc\) Assembly Firmware" | < 14.3 Search vendor "Emerson" for product "Se4100 Simplex Ethernet I\/o Card \(eioc\) Assembly Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Se4100 Simplex Ethernet I\/o Card \(eioc\) Assembly Search vendor "Emerson" for product "Se4100 Simplex Ethernet I\/o Card \(eioc\) Assembly" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Se4101 Simplex Ethernet I\/o Card \(eioc\) Assembly Firmware Search vendor "Emerson" for product "Se4101 Simplex Ethernet I\/o Card \(eioc\) Assembly Firmware" | < 14.3 Search vendor "Emerson" for product "Se4101 Simplex Ethernet I\/o Card \(eioc\) Assembly Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Se4101 Simplex Ethernet I\/o Card \(eioc\) Assembly Search vendor "Emerson" for product "Se4101 Simplex Ethernet I\/o Card \(eioc\) Assembly" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Se4801t0x Redundant Wireless I\/o Card Firmware Search vendor "Emerson" for product "Se4801t0x Redundant Wireless I\/o Card Firmware" | < 14.3 Search vendor "Emerson" for product "Se4801t0x Redundant Wireless I\/o Card Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Se4801t0x Redundant Wireless I\/o Card Search vendor "Emerson" for product "Se4801t0x Redundant Wireless I\/o Card" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Ve4103 Modbus Tcp Interface For Ethernet Connected I\/o \(eioc\) Firmware Search vendor "Emerson" for product "Ve4103 Modbus Tcp Interface For Ethernet Connected I\/o \(eioc\) Firmware" | < 14.3 Search vendor "Emerson" for product "Ve4103 Modbus Tcp Interface For Ethernet Connected I\/o \(eioc\) Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Ve4103 Modbus Tcp Interface For Ethernet Connected I\/o \(eioc\) Search vendor "Emerson" for product "Ve4103 Modbus Tcp Interface For Ethernet Connected I\/o \(eioc\)" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Ve4104 Ethernet\/ip Control Tag Integration For Ethernet Connected I\/o \(eioc\) Firmware Search vendor "Emerson" for product "Ve4104 Ethernet\/ip Control Tag Integration For Ethernet Connected I\/o \(eioc\) Firmware" | < 14.3 Search vendor "Emerson" for product "Ve4104 Ethernet\/ip Control Tag Integration For Ethernet Connected I\/o \(eioc\) Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Ve4104 Ethernet\/ip Control Tag Integration For Ethernet Connected I\/o \(eioc\) Search vendor "Emerson" for product "Ve4104 Ethernet\/ip Control Tag Integration For Ethernet Connected I\/o \(eioc\)" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Ve4105 Ethernet\/ip Interface For Ethernet Connected I\/o \(eioc\) Firmware Search vendor "Emerson" for product "Ve4105 Ethernet\/ip Interface For Ethernet Connected I\/o \(eioc\) Firmware" | < 14.3 Search vendor "Emerson" for product "Ve4105 Ethernet\/ip Interface For Ethernet Connected I\/o \(eioc\) Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Ve4105 Ethernet\/ip Interface For Ethernet Connected I\/o \(eioc\) Search vendor "Emerson" for product "Ve4105 Ethernet\/ip Interface For Ethernet Connected I\/o \(eioc\)" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Ve4106 Opc-ua Client For Ethernet Connected I\/o \(eioc\) Firmware Search vendor "Emerson" for product "Ve4106 Opc-ua Client For Ethernet Connected I\/o \(eioc\) Firmware" | < 14.3 Search vendor "Emerson" for product "Ve4106 Opc-ua Client For Ethernet Connected I\/o \(eioc\) Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Ve4106 Opc-ua Client For Ethernet Connected I\/o \(eioc\) Search vendor "Emerson" for product "Ve4106 Opc-ua Client For Ethernet Connected I\/o \(eioc\)" | - | - |
Safe
|
Emerson Search vendor "Emerson" | Ve4107 Iec 61850 Mms Interface For Ethernet Connected I\/o \(eioc\) Firmware Search vendor "Emerson" for product "Ve4107 Iec 61850 Mms Interface For Ethernet Connected I\/o \(eioc\) Firmware" | < 14.3 Search vendor "Emerson" for product "Ve4107 Iec 61850 Mms Interface For Ethernet Connected I\/o \(eioc\) Firmware" and version " < 14.3" | - |
Affected
| in | Emerson Search vendor "Emerson" | Ve4107 Iec 61850 Mms Interface For Ethernet Connected I\/o \(eioc\) Search vendor "Emerson" for product "Ve4107 Iec 61850 Mms Interface For Ethernet Connected I\/o \(eioc\)" | - | - |
Safe
|