Emerson OT:ICEFALL Multiple Potential Vulnerabilities

info Tenable.ot Plugin ID 500658


The remote OT asset may be affected by a vulnerability.


The device may be vulnerable to flaws related to OT:ICEFALL. These vulnerabilities identify the insecure-by-design nature of OT devices and may not have a clear remediation path. As such, Nessus is unable to test specifically for these vulnerabilities but has identified the device to be one that was listed in the OT:ICEFALL report. Ensure your OT deployments follow best practices including accurate inventory, separation of environments, and monitoring. This plugin will trigger on any device seen by Tenable.OT that matches a family or model listed in the OT:ICEFALL report.

Note: All findings need to be manually verified based on the advisory from the vendor, once released.

This plugin only works with Tenable.ot. Please visit https://www.tenable.com/products/tenable-ot for more information.


Refer to the vendor advisory.

See Also



Plugin Details

Severity: Info

ID: 500658

Version: 1.1

Type: remote

Family: Tenable.ot

Published: 6/22/2022

Updated: 6/22/2022

Risk Information


Risk Factor: Low

Score: 3.6

Vulnerability Information

CPE: cpe:/h:emerson:ovation_ocr1100, cpe:/h:emerson:ovation_occ100, cpe:/h:emerson:ovation_ocr400, cpe:/h:emerson:roc_300, cpe:/h:emerson:roc_800, cpe:/h:emerson:dl_8000, cpe:/h:emerson:pacsystems_rx7i, cpe:/h:emerson:pacsystems_rx3i

Required KB Items: Tenable.ot/Emerson

Vulnerability Publication Date: 6/22/2022

Reference Information

CVE: CVE-2022-30261, CVE-2022-30266, CVE-2022-30263, CVE-2022-29962, CVE-2022-29963, CVE-2022-29964, CVE-2022-29965