Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-44463


Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations (All versions) when some DeltaV services are started.


Published

2022-01-28T20:15:12.137

Last Modified

2025-04-17T16:15:24.120

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.4

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-427
  • Type: Secondary
    CWE-427

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application emerson deltav 13.3.1 Yes
Application emerson deltav 14 Yes
Application emerson deltav 14 Yes
Application emerson deltav 14.3.1 Yes
Application emerson deltav r6 Yes

References