CVE-2021-44463

Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations (All versions) when some DeltaV services are started.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-21-355-04 Mitigation Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:emerson:deltav:13.3.1:*:*:*:*:*:*:*
cpe:2.3:a:emerson:deltav:14:feature_pack1:*:*:*:*:*:*
cpe:2.3:a:emerson:deltav:14:feature_pack2:*:*:*:*:*:*
cpe:2.3:a:emerson:deltav:14.3.1:*:*:*:*:*:*:*
cpe:2.3:a:emerson:deltav:r6:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-01-28 20:15

Updated : 2024-02-28 18:48


NVD link : CVE-2021-44463

Mitre link : CVE-2021-44463

CVE.ORG link : CVE-2021-44463


JSON object : View

Products Affected

emerson

  • deltav
CWE
CWE-427

Uncontrolled Search Path Element