logo

Hacking a $100K Gas Chromatograph without Owning One

ID: 6bb01cf7-74fd-5946-88ae-b3c4f1a9be0d

STIX ID: report--6bb01cf7-74fd-5946-88ae-b3c4f1a9be0d

Feed Name: Claroty Team82

Threat Score
72/100

Date Published: 2024-06-24

Date Updated: 2026-04-17

Author: Vera Mens

...
...

This blog-style technical report describes Team82’s emulation-driven vulnerability research on the Emerson Rosemount 370XA gas chromatograph. Researchers extracted and emulated the device firmware to analyze its proprietary TCP/TLS protocol and discovered multiple flaws—most notably a command injection vulnerability (CVE-2023-46687) enabling unauthenticated remote code execution and an authentication bypass (CVE-2023-51761) allowing admin password reset. The report details the emulation steps, protocol structure, exploitation examples, and notes that Emerson addressed the issues and CISA published an advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.