You are here

Emerson AMS Device Manager (ICSA-18-270-01) – Product Used in the Energy Sector

Emerson AMS Device Manager (ICSA-18-270-01) – Product Used in the Energy Sector

Created: Tuesday, October 2, 2018 - 11:25
Categories:
Cybersecurity

The NCCIC has released an advisory on improper access control and improper privilege management vulnerabilities in Emerson AMS Device Manager. Versions 12.0 to 13.5 are affected. Successful exploitation of these vulnerabilities could allow arbitrary remote code execution and malware injection. Emerson recommends users patch the affected products. The NCCIC also recommends a series of defensive measures to minimize the risk of exploitation of these vulnerabilities. NCCIC/ICS-CERT.