CVE-2020-10632
published 2022-02-24CVE-2020-10632: Inadequate folder security permissions in Emerson OpenEnterprise versions through 3.3.4 may allow modification of important configuration files, which could…
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.47%
36.9th percentile
Inadequate folder security permissions in Emerson OpenEnterprise versions through 3.3.4 may allow modification of important configuration files, which could cause the system to fail or behave in an unpredictable manner.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| emerson | openenterprise_scada_server | <= 3.3.4 | — |
| emerson | openenterprise_scada_software | unspecified – 3.3.4 | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Emerson OpenEnterprise
cisa_ics·2020-05-20·CVSS 8.8
[HIGH] Emerson OpenEnterprise
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Emerson OpenEnterprise
Last RevisedMay 20, 2020
Alert CodeICSA-20-140-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 10.0
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Emerson
- Equipment: OpenEnterprise SCADA Software
- Vulnerabilities: Missing Authentication for Critical Function, Improper Ownership Management, Inadequate Encryption Strength
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker access to OpenEnterprise configuration services or access passwords for OpenEnterprise user accounts.
## 3. TECHNICAL DETA
GHSA
GHSA-mgx9-f28j-xh8r: Inadequate folder security permissions in Emerson OpenEnterprise versions through 3
ghsa_unreviewed·2022-02-25
CVE-2020-10632 [MEDIUM] GHSA-mgx9-f28j-xh8r: Inadequate folder security permissions in Emerson OpenEnterprise versions through 3
Inadequate folder security permissions in Emerson OpenEnterprise versions through 3.3.4 may allow modification of important configuration files, which could cause the system to fail or behave in an unpredictable manner.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-24
Published