← Back to home
ICSA-20-238-02  ·  Published 2020-08-25  ·  View on CISA ICS-CERT ↗

Emerson OpenEnterprise

CVSS 3.8 LOW

Risk Summary

Successful exploitation of this vulnerability could allow an attacker access to credentials held by OpenEnterprise used for accessing field devices and external systems.

CVEs (1)

Remediations

  • Emerson recommends all users upgrade to OpenEnterprise 3.3, Service Pack 6 (3.3.6), to resolve this issue. OpenEnterprise Service Packs are available to users with access to the Emerson SupportNet system (login required). Details will be found in the downloads area.
  • Please send any questions via a SupportNet ticket or by contacting Emerson at US 800-537-9313. For users outside of the United States, please use international toll-free numbers.

Affected Vendors

Emerson

Affected Products (1)

Emerson · OpenEnterprise <= 3.3.5

Affected Sectors

Chemical, Energy, Healthcare and Public Health, Water and Wastewater Systems

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more