Emerson ValveLink Products store sensitive information in cleartext in memory. The sensitive memory might be saved to disk, stored in a core dump, or remain uncleared if the product crashes, or if the programmer does not properly clear the memory before freeing it.
The vulnerability (CWE-316) consists of sensitive data — such as passwords or authentication keys — being stored in process memory without encryption. In the event of product failure or improper memory deallocation by the developer, this data can be written to disk as a core dump or swap file. An attacker or unauthorized user with access to the file system or device memory can read this data without any additional cryptanalysis tools.
An attacker can gain access to sensitive information (e.g., authentication credentials) stored in memory or saved to disk, which can lead to system takeover or further compromise of industrial infrastructure.
Security patches available from the manufacturer should be applied according to the following references: https://www.cisa.gov/news-events/ics-advisories/icsa-25-189-01 and https://www.emerson.com/en-us/support/security-notifications and https://www.emerson.com/en-us/support/software-downloads-drivers
Emerson ValveLink products — specific versions indicated in the manufacturer's references (ICSA-25-189-01 and Emerson security notifications)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X