CVE-2014-2349: Emerson Deltav

Medium severity, CVSS 4.6. EPSS: 0.7% chance of exploitation in the next 30 days.

Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that uses the telnet program.

Affected products

  • Emerson Deltav: version 10.3.1 only; version 11.3 only; version 11.3.1 only; version 12.3 only

Published 2014-05-22. Last modified 2026-06-17.