MEDIUM · 6.9

CVE-2023-49716

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote computer.

Vulnerability Description

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote computer.

CVSS Score

6.9

MEDIUM

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
LOW
Availability
HIGH

Affected Products

VendorProductVersions
EmersonGc370Xa Firmware4.1.5
EmersonGc370Xa-
EmersonGc700Xa Firmware4.1.5
EmersonGc700Xa-
EmersonGc1500Xa Firmware4.1.5
EmersonGc1500Xa-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-49716?

CVE-2023-49716 is a vulnerability with a CVSS score of 6.9 (MEDIUM). In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote computer.

How severe is CVE-2023-49716?

CVE-2023-49716 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-49716?

Check the references section above for vendor advisories and patch information. Affected products include: Emerson Gc370Xa Firmware, Emerson Gc370Xa, Emerson Gc700Xa Firmware, Emerson Gc700Xa, Emerson Gc1500Xa Firmware.