#VU16938 Authorization bypass in DeltaV - CVE-2018-19021
Published: January 10, 2019 / Updated: January 11, 2019
DeltaV
Emerson
Description
The vulnerability allows an adjacent attacker to bypass authentication on the target system.
The vulnerability exists due to insufficient validation of user-supplied input. An adjacent unauthenticated attacker can supply a specially crafted script to bypass the authentication of a maintenance port of a service and cause a denial of service.