CVE-2022-2791: Emerson Proficy

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File with Dangerous Type, and will upload any file written into the PLC logic folder to the connected PLC.

Affected products

  • Emerson Proficy: up to and including 9.00

Published 2022-11-22. Last modified 2026-06-17.