The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications between a master terminal and RTUs. Opcode 203 of this protocol allows a master terminal to transfer files to and from the flash filesystem and carrying out arbitrary file and directory read, write, and delete operations.
2022-08-16T13:15:11.220
2024-11-21T07:02:27.773
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | emerson | dl8000_firmware | ≤ 2022-05-02 | Yes |
Hardware | emerson | dl8000 | - | No |
Operating System | emerson | roc809_firmware | < 2022-05-02 | Yes |
Hardware | emerson | roc809 | - | No |
Operating System | emerson | roc800l_firmware | ≤ 2022-05-02 | Yes |
Hardware | emerson | roc800l | - | No |
Operating System | emerson | fb3000_rtu_firmware | ≤ 2022-05-02 | Yes |
Hardware | emerson | fb3000_rtu | - | No |
Operating System | emerson | roc827_firmware | < 2022-05-02 | Yes |
Hardware | emerson | roc827 | - | No |