Back

HIGH

Emerson DeltaV Use of Hard-coded Credentials

Published May 22, 2014

Description

Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that uses the telnet program.

Affected products

Remediation

Vendor solution

Emerson has created a patch to mitigate these vulnerabilities. Emerson has distributed a notification (KBA NK-1400-0031) that provides details of the vulnerabilities, recommended mitigations, and instructions on obtaining and installing the patch. This document is available on Emerson’s support site to users who have support contracts with Emerson. If you do not have access to this site and need to apply the patch, please contact customer service at 1‑800‑833‑8314.

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published May 22, 2014
Updated Oct 31, 2025
Reserved Mar 13, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a