Back to overview

CVE-2020-10640

CRITICAL
10.0
CVSS 3.1
Description
Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service.

Metadata

CVE ID
CVE-2020-10640
State
PUBLISHED
Assigner
icscert
Reserved
2020-03-16 00:00 UTC
Published
2022-02-24 18:50 UTC
Last updated
2025-04-16 16:44 UTC
Primary CWE
CWE-306
CWE-306: Missing Authentication for Critical Function
Vendor / Product
Emerson / OpenEnterprise SCADA Software
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Emerson OpenEnterprise SCADA Software unspecified ≤ 3.3.4
Weakness (CWE)
CWESourceDescription
CWE-306 cna CWE-306: Missing Authentication for Critical Function
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview