Emerson Deltav Improper Restriction of Operations within the Bounds of a Memory Buffer

PORTSERV.exe in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph allows remote attackers to cause a denial of service (daemon crash) via a crafted (1) TCP or (2) UDP packet to port 111.


Refer to vendor advisory for Security Updates

Plugin Details

Severity: Medium

ID: 500464

Version: 1.0

Type: local

Family: SCADA

Published: 8/10/2021

Updated: 8/10/2021

Risk Information

CVSS Score Source: CVE-2012-1816


Risk Factor: Medium

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

CPE: cpe:2.3:a:emerson:deltav:10.3.1:*:*:*:*:*:*:*, cpe:2.3:a:emerson:deltav:11.3.1:*:*:*:*:*:*:*, cpe:2.3:a:emerson:deltav:11.3:*:*:*:*:*:*:*, cpe:2.3:a:emerson:deltav:9.3.1:*:*:*:*:*:*:*, cpe:2.3:a:emerson:deltav_proessentials_scientific_graph:*:*:*:*:*:*:*, cpe:2.3:a:emerson:deltav_workstation:10.3.1:*:*:*:*:*:*:*, cpe:2.3:a:emerson:deltav_workstation:11.3.1:*:*:*:*:*:*:*, cpe:2.3:a:emerson:deltav_workstation:11.3:*:*:*:*:*:*:*, cpe:2.3:a:emerson:deltav_workstation:9.3.1:*:*:*:*:*:*:*

Patch Publication Date: 6/8/2012

Vulnerability Publication Date: 6/8/2012

Reference Information

CVE: CVE-2012-1816