Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 15, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 15, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 15, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 15, 2025

      Intel’s latest Arc graphics driver is ready for DOOM: The Dark Ages, launching for Premium Edition owners on PC today

      May 15, 2025

      NVIDIA’s drivers are causing big problems for DOOM: The Dark Ages, but some fixes are available

      May 15, 2025

      Capcom breaks all-time profit records with 10% income growth after Monster Hunter Wilds sold over 10 million copies in a month

      May 15, 2025

      Microsoft plans to lay off 3% of its workforce, reportedly targeting management cuts as it changes to fit a “dynamic marketplace”

      May 15, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      A cross-platform Markdown note-taking application

      May 15, 2025
      Recent

      A cross-platform Markdown note-taking application

      May 15, 2025

      AI Assistant Demo & Tips for Enterprise Projects

      May 15, 2025

      Celebrating Global Accessibility Awareness Day (GAAD)

      May 15, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Intel’s latest Arc graphics driver is ready for DOOM: The Dark Ages, launching for Premium Edition owners on PC today

      May 15, 2025
      Recent

      Intel’s latest Arc graphics driver is ready for DOOM: The Dark Ages, launching for Premium Edition owners on PC today

      May 15, 2025

      NVIDIA’s drivers are causing big problems for DOOM: The Dark Ages, but some fixes are available

      May 15, 2025

      Capcom breaks all-time profit records with 10% income growth after Monster Hunter Wilds sold over 10 million copies in a month

      May 15, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Researchers Uncover Flaws in Widely Used Emerson Rosemount Industrial Gas Chromatographs

    Researchers Uncover Flaws in Widely Used Emerson Rosemount Industrial Gas Chromatographs

    June 28, 2024

    Security experts have identified multiple vulnerabilities in widely used industrial gas chromatographs manufactured by Emerson Rosemount. These flaws could potentially allow malicious actors to access sensitive information, disrupt operations and execute unauthorized commands.

    Gas chromatographs are critical instruments used for analyzing chemical compounds across a range of industries, including environmental facilities, hospitals, and food processing companies. These devices are critical for ensuring the accuracy of gas measurements and the safety of the environment, patients, and consumers.

    Flaws in Emerson Rosemount Gas Chromatographs

    Operational technology security firm Claroty discovered the vulnerabilities, which include two command injection flaws and two authentication bypass issues. If exploited, these flaws could enable unauthenticated attackers to run arbitrary commands, access sensitive data and gain administrative control.

    Source: Wikipedia Emulated system (Source: claroty.com)

    To study the Emerson Rosemount 370XA gas chromatograph, commonly used in industrial settings for gas analysis, the researchers took efforts to emulate the systems. This complex process was undertaken because the physical device could cost over $100,000 while the research was limited to a six-week project.

    The emulation process involved download and extraction of the device firmware from the official Emerson Rosemount website, and a search for an application that could implements its proprietary protocols. The researchers used the QEMU emulator to emulate the PowerPC architecture used by the gas chromatograph and run the extracted firmware. Upon investigation, the researchers were able to uncover four key vulnerabilities:

    CVE-2023-46687: Allows remote execution of root-level commands without authentication (CVSS score: 9.8)
    CVE-2023-49716: Enables authenticated users to run arbitrary commands remotely (CVSS score: 6.9)
    CVE-2023-51761: Permits unauthenticated users to bypass authentication and gain admin access by resetting passwords (CVSS score: 8.3)
    CVE-2023-43609: Allows unauthenticated users to access sensitive information or cause denial-of-service (CVSS score: 6.9)

    The U.S. Cybersecurity and Infrastructure Security Agency issued an advisory in January warning that successful attacks could lead to “denial-of-service conditions” and unauthorized system access. The affected models include GC370XA, GC700XA and GC1500XA running firmware versions 4.1.5 and earlier.

    Industry Impact and Mitigation

    Gas chromatographs play a crucial role in various sectors, from environmental monitoring to medical diagnostics. Compromised devices could have far-reaching consequences.

    In food processing, attacks on chromatographs might prevent accurate bacteria detection, halting production. In healthcare settings, disrupted blood sample analysis could impact patient care.

    Emerson has released updated firmware addressing these vulnerabilities. The Claroty researchers said they “appreciate Emerson for its swift response and cooperation, which demonstrates their dedication to our shared goal.”

    Emerson advises customers to apply the patches and implement best practices in the cybersecurity industry according to current standards.

    The firm stated, “In addition, Emerson recommends end users continue to utilize current cybersecurity industry best practices and in the event such infrastructure is not implemented within an end user’s network, action should be taken to ensure the Affected Product is connected to a well-protected network and not
    connected to the Internet.

    In its advisory CISA shared the following recommendations for securing these systems:

    Minimize network exposure: Ensure that control system devices and/or systems,  are not publicly accessible from the internet.
    Locate control system networks:  Place remote devices behind firewalls and isolate them from business networks
    Secure Remote Access: Use Virtual Private Networks (VPNs) to secure remote access. However, the agency also warned of potential inherent risks in VPNs, asking organizations and businesses to be aware of them.

    CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures,” the advisory stated.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleSnailLoad Allows Attackers to Trace Visited Websites By Measuring Network Latency
    Next Article Russian hackers read the emails you sent us, Microsoft warns more customers

    Related Posts

    Security

    Nmap 7.96 Launches with Lightning-Fast DNS and 612 Scripts

    May 16, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-4732 – TOTOLINK A3002R/A3002RU HTTP POST Request Handler Buffer Overflow

    May 16, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    Deepfake Defense in the Age of AI

    Development

    Windows 11’s upcoming Continue from Phone could be seamless mobile-desktop integration at its best

    Development

    Smashing Security podcast #398: Fake CAPTCHAs, Harmageddon, and Krispy Kreme

    Development

    Fusion Developer Preview is released: Write PHP inside your Vue and React components

    Development

    Highlights

    Development

    Optimizing UI Development: Storybook Essentials

    June 21, 2024

    Introduction: Storybook works alongside your app, giving you a separate area to create and test…

    Google Wallet now alerts you to loyalty card benefits you’re missing out on

    February 19, 2025

    Celebrating the Visionary Genius of Digital Marketing: Srinidhi Ranganathan and His Musical Masterpiece “I Cannot Live Without YouTube”

    June 18, 2024

    LLM Reasoning Benchmarks are Statistically Fragile: New Study Shows Reinforcement Learning RL Gains often Fall within Random Variance

    April 15, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.