PatchSiren cyber security CVE debrief
CVE-2016-9347 Emerson CVE debrief
CVE-2016-9347 is a medium-severity issue affecting Emerson DeltaV Wireless I/O Cards running firmware v13.3. The problem is that SSH is enabled unnecessarily on the SE4801T0X and SE4801T1X cards, increasing the management exposure of the device. Defenders should verify whether these cards are present, limit SSH exposure, and follow the linked vendor or ICS-CERT guidance for supported hardening steps.
- Vendor
- Emerson
- Product
- CVE-2016-9347
- CVSS
- MEDIUM 5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-13
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-13
- Advisory updated
- 2026-05-13
Who should care
OT/ICS operators using Emerson DeltaV Wireless I/O Cards, plant network and security teams, and administrators responsible for managing SE4801T0X or SE4801T1X devices running firmware v13.3.
Technical summary
The supplied NVD record says Emerson SE4801T0X Redundant Wireless I/O Card V13.3 and SE4801T1X Simplex Wireless I/O Card V13.3 are affected because SSH functionality is enabled unnecessarily. NVD maps the issue to CWE-254 and rates it CVSS v3.0 5.0 with vector AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L, indicating adjacent-network exposure, high attack complexity, and low impact to confidentiality, integrity, and availability.
Defensive priority
Medium: the score is moderate, but this still matters in industrial environments because it exposes an unnecessary management service on affected DeltaV wireless I/O cards.
Recommended defensive actions
- Inventory DeltaV Wireless I/O Cards to confirm whether SE4801T0X or SE4801T1X devices are running firmware v13.3.
- Review Emerson and ICS-CERT guidance for supported hardening or mitigation steps for CVE-2016-9347.
- If SSH is not required for your operational workflow, restrict or disable access using vendor-supported configuration methods.
- Segment the OT network so only approved management hosts can reach the affected devices.
- Validate any configuration change in a maintenance window and monitor for unexpected SSH access attempts.
Evidence notes
The supplied corpus includes the NVD entry, which lists the affected CPEs for SE4801T0X firmware 13.3 and SE4801T1X firmware 13.3, the CVSS v3.0 vector, and CWE-254. It also references SecurityFocus BID 94586 and the ICS-CERT advisory ICSA-16-334-03. No exploit code or weaponized reproduction details are present in the supplied sources.
Official resources
-
CVE-2016-9347 CVE record
CVE.org
-
CVE-2016-9347 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, US Government Resource
CVE-2016-9347 was published in the supplied official record on 2017-02-13T21:59:01.830Z. The later 2026-05-13 modification timestamp reflects database updates and should not be treated as the original disclosure date.