CVE-2024-1156: Emerson Data Record Ad

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges.

Affected products

  • Emerson Data Record Ad: up to and including 2.0.1
  • Emerson Flexlogger: up to and including 2022_q3
  • Emerson G Web Development Software: up to and including 2022_q3
  • Emerson Labview Nxg: version 5.1 only
  • Emerson Specification Compliance Manager: up to and including 2023_q4
  • Emerson Static Test Software Suite: up to and including 1.2
  • Emerson Sts Software Bundle: up to and including 21.0
  • Emerson Systemlink Server: before 2024_q1 (fixed in 2024_q1)

Published 2024-02-20. Last modified 2026-06-17.