CVE-2022-29960

Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES with hardcoded cryptographic keys is used for protection of certain system credentials, engineering files, and sensitive utilities.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-181-03 Not Applicable Third Party Advisory US Government Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-221-03 Third Party Advisory US Government Resource
https://www.forescout.com/blog/ Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:emerson:openbsi:*:*:*:*:*:*:*:*
cpe:2.3:a:emerson:openbsi:5.9:-:*:*:*:*:*:*
cpe:2.3:a:emerson:openbsi:5.9:sp1:*:*:*:*:*:*
cpe:2.3:a:emerson:openbsi:5.9:sp2:*:*:*:*:*:*
cpe:2.3:a:emerson:openbsi:5.9:sp3:*:*:*:*:*:*

History

13 Feb 2024, 15:57

Type Values Removed Values Added
CWE CWE-327 CWE-798

16 Aug 2022, 17:55

Type Values Removed Values Added
CPE cpe:2.3:a:emerson:openbsi:5.9:sp1:*:*:*:*:*:*
cpe:2.3:a:emerson:openbsi:5.9:-:*:*:*:*:*:*
cpe:2.3:a:emerson:openbsi:5.9:sp3:*:*:*:*:*:*
cpe:2.3:a:emerson:openbsi:5.9:sp2:*:*:*:*:*:*
References (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-22-221-03 - (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-22-221-03 - Third Party Advisory, US Government Resource

16 Aug 2022, 13:15

Type Values Removed Values Added
References
  • (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-22-221-03 -

03 Aug 2022, 14:49

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-22-181-03 - (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-22-181-03 - Not Applicable, Third Party Advisory, US Government Resource
References (MISC) https://www.forescout.com/blog/ - (MISC) https://www.forescout.com/blog/ - Third Party Advisory
CPE cpe:2.3:a:emerson:openbsi:*:*:*:*:*:*:*:*
CWE CWE-327

26 Jul 2022, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-07-26 22:15

Updated : 2024-02-13 15:57


NVD link : CVE-2022-29960

Mitre link : CVE-2022-29960

CVE.ORG link : CVE-2022-29960


JSON object : View

Products Affected

emerson

  • openbsi
CWE
CWE-798

Use of Hard-coded Credentials