Emerson's vulnerability footprint spans industrial automation and control systems, including its widely deployed DeltaV distributed control platform and wireless gateway products, which serve critical infrastructure and manufacturing environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, though the exposure reflects the legacy engineering and operational-technology constraints of industrial systems rather than a modern software stack. The recurring weakness classes—path traversal, missing authentication for critical functions, hard-coded credentials, and insufficient data-authenticity verification—are endemic to control systems where network isolation has historically substituted for application-layer security, and where legacy protocols and firmware updates present remediation challenges distinct from enterprise IT. Defenders should treat Emerson's advisories as high-priority for any operational-technology environment and prioritize network segmentation and access restrictions where patching cycles extend beyond IT timelines. Live severity and current exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Emerson over time
Signals from CVEs in this vendor scope (85 CVEs).
85 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45420CRITICAL Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker | Feb 14, 2022 | 9.8 | 53 | NO | YES |
CVE-2021-45427CRITICAL Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An attacker can browse and delete files without any authenticatio | Dec 30, 2021 | 9.8 | 41 | NO | NO |
CVE-2020-12030CRITICAL There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN setting, the internal gateway fir | Sep 29, 2021 | 10.0 | 30 | NO | NO |
CVE-2020-6970CRITICAL A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are in use) and all versions of OpenEnterpri | Feb 19, 2020 | 9.8 | 30 | NO | NO |
CVE-2018-14804CRITICAL Emerson AMS Device Manager v12.0 to v13.5. A specially crafted script may be run that allows arbitrary remote code execution. | Oct 1, 2018 | 9.8 | 30 | NO | NO |
CVE-2023-43609CRITICAL In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain access to sensitive information or cause a denial-of-service | Feb 9, 2024 | 9.1 | 29 | NO | NO |
CVE-2022-30264CRITICAL The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications betwe | Aug 16, 2022 | 9.8 | 29 | NO | NO |
CVE-2021-27459CRITICAL A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The webserver of the affected products allows unvalidated files to be uploaded, whi | May 20, 2021 | 9.8 | 29 | NO | NO |
CVE-2019-10967HIGH In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a stack-based buffer overflow vulnerability in the embedded third-party FTP server involves improper handling of a long file | May 28, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-10965HIGH In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a heap-based buffer overflow vulnerability in the embedded third-party FTP server involves improper handling of a long comma | May 28, 2019 | 8.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (85 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Emerson.
Media articles that mention a CVE ID that affects a product developed by Emerson — matched by CVE ID, not by vendor name.