Emerson PAC Machine Edition 9.80 contains an unquoted service path vulnerability in the TrapiServer service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissions during service startup.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 14 Jan 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Emerson
Emerson pac Machine Edition
Vendors & Products Emerson
Emerson pac Machine Edition

Tue, 13 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Emerson PAC Machine Edition 9.80 contains an unquoted service path vulnerability in the TrapiServer service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissions during service startup.
Title Emerson PAC Machine Edition 9.80 Build 8695 - 'TrapiServer' Unquoted Service Path
Weaknesses CWE-428
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-01-13T22:51:58.910Z

Reserved: 2026-01-11T13:34:26.328Z

Link: CVE-2022-50930

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-13T23:15:57.583

Modified: 2026-01-13T23:15:57.583

Link: CVE-2022-50930

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-14T10:49:25Z

Weaknesses