Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES with hardcoded cryptographic keys is used for protection of certain system credentials, engineering files, and sensitive utilities.
References
Link | Resource |
---|---|
https://www.forescout.com/blog/ | Third Party Advisory |
https://www.cisa.gov/uscert/ics/advisories/icsa-22-181-03 | Not Applicable Third Party Advisory US Government Resource |
https://www.cisa.gov/uscert/ics/advisories/icsa-22-221-03 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-07-26 15:15
Updated : 2022-08-16 10:55
NVD link : CVE-2022-29960
Mitre link : CVE-2022-29960
JSON object : View
CWE
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
Products Affected
emerson
- openbsi