Vulnerability Details CVE-2020-16235
Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through version 3.3.5, to access field devices and external systems to be obtained.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 2.1%
CVSS Severity
CVSS v3 Score 3.8
CVSS v2 Score 2.1
Products affected by CVE-2020-16235
-
cpe:2.3:a:emerson:openenterprise_scada_server:2.8.3
-
cpe:2.3:a:emerson:openenterprise_scada_server:3.1
-
cpe:2.3:a:emerson:openenterprise_scada_server:3.3.3
-
cpe:2.3:a:emerson:openenterprise_scada_server:3.3.5