The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications between a master terminal and RTUs. Opcode 203 of this protocol allows a master terminal to transfer files to and from the flash filesystem and carrying out arbitrary file and directory read, write, and delete operations.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-08-16T12:42:58

Updated: 2024-08-03T06:40:47.846Z

Reserved: 2022-05-04T00:00:00

Link: CVE-2022-30264

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-08-16T13:15:11.220

Modified: 2022-08-17T19:35:10.337

Link: CVE-2022-30264

cve-icon Redhat

No data.