CVE-2022-30264
The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications between a master terminal and RTUs. Opcode 203 of this protocol allows a master terminal to transfer files to and from the flash filesystem and carrying out arbitrary file and directory read, write, and delete operations.
Published:Aug 16, 2022
Last Modified:Nov 21, 2024
EPS:Aug 16, 2022
EPSS Score:0.00119
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Emerson
Product
Dl8000
Emerson
Dl8000
Vendor
Emerson
Product
Dl8000 Firmware
Emerson
Dl8000 Firmware
Vendor
Emerson
Product
Fb3000 Rtu
Emerson
Fb3000 Rtu
Vendor
Emerson
Product
Fb3000 Rtu Firmware
Emerson
Fb3000 Rtu Firmware
Vendor
Emerson
Product
Roc800l
Emerson
Roc800l
Vendor
Emerson
Product
Roc800l Firmware
Emerson
Roc800l Firmware
Vendor
Emerson
Product
Roc809
Emerson
Roc809
Vendor
Emerson
Product
Roc809 Firmware
Emerson
Roc809 Firmware
Vendor
Emerson
Product
Roc827
Emerson
Roc827
Vendor
Emerson
Product
Roc827 Firmware
Emerson
Roc827 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
