PatchSiren cyber security CVE debrief
CVE-2022-30265 Emerson CVE debrief
A medium-severity vulnerability in Emerson PAC Machine Edition and PACSystem PLCs allows control logic to be downloaded without cryptographic authentication. The flaw affects logic written in IEC 61131-3 languages or C/ELF binary blocks, enabling an attacker with local access and high privileges to modify PLC logic without detection. Published June 6, 2024, this vulnerability carries a CVSS 3.1 score of 4.4 (AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N), indicating local attack vector with high privilege requirements but significant integrity impact. No known exploitation in ransomware campaigns has been reported.
- Vendor
- Emerson
- Product
- PAC Machine Edition
- CVSS
- MEDIUM 4.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-06-06
- Original CVE updated
- 2024-06-06
- Advisory published
- 2024-06-06
- Advisory updated
- 2024-06-06
Who should care
Industrial control system operators, OT security engineers, and asset owners using Emerson PACSystem PLCs in manufacturing, energy, water/wastewater, and critical infrastructure environments should prioritize this vulnerability. Organizations with remote or shared engineering access, limited physical security controls, or compliance requirements for control system integrity (NERC CIP, IEC 62443) face elevated risk. Security teams should coordinate with plant engineers to assess exposure and implement compensating controls where patching is constrained by operational requirements.
Technical summary
The vulnerability exists because control logic downloaded to Emerson PACSystem PLCs—including PAC Machine Edition, RX3i, RSTi-EP, and VersaMax product lines—is not cryptographically authenticated. This applies to logic implemented in IEC 61131-3 standard languages (Ladder Diagram, Structured Text, Function Block Diagram, Instruction List, Sequential Function Chart) as well as C-language implementations compiled to ELF binary blocks. An attacker with local access to the engineering workstation and high-privilege credentials could modify and download malicious control logic without cryptographic verification by the PLC. The CVSS 3.1 vector (AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N) reflects this local attack scenario with no confidentiality or availability impact but high integrity impact. The vulnerability does not affect confidentiality or availability of the PLC, but compromises the integrity of control logic execution.
Defensive priority
medium
Recommended defensive actions
- Implement strict physical and personnel security controls per vendor guidance to prevent unauthorized local access to engineering workstations and PLCs
- Deploy network segmentation to isolate control system networks from enterprise IT infrastructure
- Disable unnecessary Ethernet services on affected PLCs per vendor documentation
- Ensure SRP6-a authentication is enabled where available; if not available, follow vendor reference architecture recommendations
- Apply defense-in-depth strategies including monitoring for unauthorized logic downloads and anomalous PLC behavior
- Review and implement CISA ICS recommended practices for industrial control system security
- Establish secure login procedures and enforce least-privilege access for engineering personnel
- Maintain offline backups of verified control logic to enable rapid restoration if unauthorized modifications are detected
Evidence notes
CISA ICS advisory ICSA-24-158-01 documents that control logic downloaded to affected PLCs lacks cryptographic authentication, regardless of whether implemented in IEC 61131-3 languages or as C-based ELF binary blocks. The advisory was published June 6, 2024, with initial revision history confirming this date.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-30265 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-30265
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-30265 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-30265
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-158-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-158-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.