PatchSiren cyber security CVE debrief
CVE-2022-30263 Emerson CVE debrief
CVE-2022-30263 (published 2024-06-06) is a MEDIUM severity vulnerability (CVSS 5.9) affecting Emerson PAC Machine Edition and multiple PACSystem PLC families (RXi, RX3i, RSTi-EP, VersaMax) as well as Fanuc VersaMax. The core issue is cleartext credential transmission in the affected products' protocol, which could allow network-based attackers to retrieve credentials and gain PLC control. The advisory notes that cryptographically secure authentication via SRP-6a protocol is supported and recommended as a countermeasure. Enabling authentication prevents replay attacks and forces attackers to intercept and modify active connections rather than simply capturing credentials. Network segmentation through non-routing control networks adds another layer of defense by requiring network topology compromise before SRTP packets can be intercepted.
- Vendor
- Emerson
- Product
- PAC Machine Edition
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-06-06
- Original CVE updated
- 2024-06-06
- Advisory published
- 2024-06-06
- Advisory updated
- 2024-06-06
Who should care
OT security teams operating Emerson PACSystem RXi, RX3i, RSTi-EP, or VersaMax PLCs; industrial control system administrators responsible for PLC authentication configuration; network architects designing segmented control system environments
Technical summary
Affected Emerson PACSystem products transmit authentication credentials in cleartext, enabling credential theft and PLC compromise via passive network monitoring. The vulnerability is mitigated by enabling SRP-6a (Secure Remote Password) authentication, which provides cryptographic protection against credential exposure and replay attacks. Defense in depth requires network segmentation (non-routing control networks) to limit packet interception opportunities.
Defensive priority
medium
Recommended defensive actions
- Enable SRP-6a cryptographically secure authentication on all affected PLCs per vendor documentation
- Implement non-routing control network architecture to prevent SRTP packet interception
- Review PACSystems RXi, RX3i and RSTi-EP Secure Deployment Guide (GFK-2830Y) sections 2.4, 4.3.3, 4.3.4, and 5.2.1.1 for configuration guidance
- Disable unnecessary Ethernet services where SRP-6a is not in use
- Apply personnel and physical security perimeter protections per vendor recommendations
Evidence notes
CISA ICS advisory ICSA-24-158-01 published 2024-06-06 documents this vulnerability affecting six Emerson product lines. The advisory explicitly states SRP-6a authentication is supported and recommended to mitigate credential exposure. CVSS 3.1 vector AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H reflects physical access requirements limiting attack surface.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-30263 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-30263
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-30263 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-30263
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-158-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-158-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.