Emerson Update
3566Warning Date
Severity Level
Warning Number
Target Sector
19 February, 2020
● High
2020-932
Energy - Transportation - Water and Utilities - Commercial Facilities
Description:
Emerson has released security update to address a vulnerability in the following versions of OpenEnterprise SCADA:
- OpenEnterprise Server 2.83 is affected if Modbus or ROC Interfaces have been installed and are in use
- OpenEnterprise 3.1 through 3.3.3, all versions
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Buffer overflow
- Execute arbitrary command remotely
Best practice and Recommendations:
The CERT team encourages users to review Emerson security advisory and upgrade to OpenEnterprise 3.3, Service Pack 4 (3.3.4)