PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-30263 Emerson CVE debrief

CVE-2022-30263 (published 2024-06-06) is a MEDIUM severity vulnerability (CVSS 5.9) affecting Emerson PAC Machine Edition and multiple PACSystem PLC families (RXi, RX3i, RSTi-EP, VersaMax) as well as Fanuc VersaMax. The core issue is cleartext credential transmission in the affected products' protocol, which could allow network-based attackers to retrieve credentials and gain PLC control. The advisory notes that cryptographically secure authentication via SRP-6a protocol is supported and recommended as a countermeasure. Enabling authentication prevents replay attacks and forces attackers to intercept and modify active connections rather than simply capturing credentials. Network segmentation through non-routing control networks adds another layer of defense by requiring network topology compromise before SRTP packets can be intercepted.

Vendor
Emerson
Product
PAC Machine Edition
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2024-06-06
Original CVE updated
2024-06-06
Advisory published
2024-06-06
Advisory updated
2024-06-06

Who should care

OT security teams operating Emerson PACSystem RXi, RX3i, RSTi-EP, or VersaMax PLCs; industrial control system administrators responsible for PLC authentication configuration; network architects designing segmented control system environments

Technical summary

Affected Emerson PACSystem products transmit authentication credentials in cleartext, enabling credential theft and PLC compromise via passive network monitoring. The vulnerability is mitigated by enabling SRP-6a (Secure Remote Password) authentication, which provides cryptographic protection against credential exposure and replay attacks. Defense in depth requires network segmentation (non-routing control networks) to limit packet interception opportunities.

Defensive priority

medium

Recommended defensive actions

  • Enable SRP-6a cryptographically secure authentication on all affected PLCs per vendor documentation
  • Implement non-routing control network architecture to prevent SRTP packet interception
  • Review PACSystems RXi, RX3i and RSTi-EP Secure Deployment Guide (GFK-2830Y) sections 2.4, 4.3.3, 4.3.4, and 5.2.1.1 for configuration guidance
  • Disable unnecessary Ethernet services where SRP-6a is not in use
  • Apply personnel and physical security perimeter protections per vendor recommendations

Evidence notes

CISA ICS advisory ICSA-24-158-01 published 2024-06-06 documents this vulnerability affecting six Emerson product lines. The advisory explicitly states SRP-6a authentication is supported and recommended to mitigate credential exposure. CVSS 3.1 vector AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H reflects physical access requirements limiting attack surface.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-30263 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-30263

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-30263 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-30263

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-158-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-158-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.