CVE-2013-0694

T

he Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier have hardcoded credentials in a ROM, which makes it easier for remote attackers to obtain shell access to the underlying OS by leveraging knowledge of the ROM contents from a product installation elsewhere.

References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:enea:ose:*:*:*:*:*:*:*:*
cpe:2.3:h:emerson:dl_8000_remote_terminal_unit:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:enea:ose:*:*:*:*:*:*:*:*
cpe:2.3:h:emerson:roc_800l_remote_terminal_unit:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:enea:ose:*:*:*:*:*:*:*:*
cpe:2.3:h:emerson:roc_800_remote_terminal_unit:-:*:*:*:*:*:*:*

History

21 Nov 2024, 01:48

Type Values Removed Values Added
References () http://ics-cert.us-cert.gov/advisories/ICSA-13-259-01 - US Government Resource () http://ics-cert.us-cert.gov/advisories/ICSA-13-259-01 - US Government Resource

Information

Published : 2013-10-03 11:04

Updated : 2025-04-11 00:51


NVD link : CVE-2013-0694

Mitre link : CVE-2013-0694

CVE.ORG link : CVE-2013-0694


JSON object : View

CWE
CWE-255

Credentials Management Errors