CVE-2021-44463
Severity CVSS v4.0:
Pending analysis
Type:
CWE-427
Uncontrolled Search Path Element
Publication date:
28/01/2022
Last modified:
17/04/2025
Description
Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations (All versions) when some DeltaV services are started.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Base Score 2.0
6.90
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:emerson:deltav:13.3.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:emerson:deltav:14:feature_pack1:*:*:*:*:*:* | ||
| cpe:2.3:a:emerson:deltav:14:feature_pack2:*:*:*:*:*:* | ||
| cpe:2.3:a:emerson:deltav:14.3.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:emerson:deltav:r6:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



