There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN setting, the internal gateway firewall becomes disabled resulting in exposure of all ports used by the gateway.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-4346 There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN setting, the internal gateway firewall becomes disabled resulting in exposure of all ports used by the gateway.
Fixes

Solution

Emerson recommends end users update the firmware on VLAN-enabled Version 4 gateways as soon as possible. If the VLAN feature is not enabled, no immediate action is necessary. Please see Emerson’s cybersecurity notification alert number EMR.RMT20001-1 for more information.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-04T11:48:57.679Z

Reserved: 2020-04-21T00:00:00

Link: CVE-2020-12030

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-09-29T20:15:07.870

Modified: 2024-11-21T04:59:08.803

Link: CVE-2020-12030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.