CVE-2022-30264 - CVE House
Back to Database
Status published Critical CVE-2022-30264

The Emerson ROC and FloBoss RTU product lines through 2022-05-02...

Vulnerability Description

The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications between a master terminal and RTUs. Opcode 203 of this protocol allows a master terminal to transfer files to and from the flash filesystem and carrying out arbitrary file and directory read, write, and delete operations.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-30264

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

dl8000 firmware, roc809 firmware, roc800l firmware, fb3000 rtu firmware, roc827 firmware
Vulnerable Versions:
0

Timeline

Official Publish: August 16th, 2022
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.