Emerson Rosemount GC370XA, GC700XA, GC1500XA
These Emerson Rosemount gas chromatographs contain multiple command injection and authentication bypass vulnerabilities. An unauthenticated attacker with network access can run arbitrary commands with administrative privileges, access sensitive instrument data, cause the device to stop responding, or bypass authentication controls. Affected products are the GC370XA, GC700XA, and GC1500XA running firmware version 4.1.5 or earlier. The vulnerabilities are classified as high-complexity attacks, and no public exploitation has been reported. However, Emerson has not announced fixed firmware versions and recommends contacting support for patching options.
- Network access to the device's listening port
- Device must be powered on and running firmware version 4.1.5 or earlier
Patching may require device reboot — plan for process interruption
/api/v1/advisories/ae9478d9-cf5e-4601-81cb-073704e823d0Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.