CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

emerson

x-stream_enhanced_xefd_firmware

7 known vulnerabilities · sorted by CVSS score

CVE-2021-27459
CRITICAL9.8

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The webserver of the affected products allows unvalidated files to be uploaded, which an attacker could utilize to execute arbitrary code.

emerson / x-stream_enhanced_xegp_firmware+3
Network
Published May 20, 2021
CVE-2021-27457
HIGH7.5

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected products utilize a weak encryption algorithm for storage of sensitive data, which may allow an attacker to more easily obtain credentials used for access.

emerson / x-stream_enhanced_xegp_firmware+3
Network
Published May 20, 2021
CVE-2020-27254
HIGH7.5

Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products are vulnerable to improper authentication for accessing log and backup data, which could allow an attacker with a specially crafted URL to obtain access to sensitive information.

emerson / x-stream_enhanced_xegp_firmware+3
Network
Published Dec 21, 2020
CVE-2021-27461
HIGH7.5

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected webserver applications allow access to stored data that can be obtained by using specially crafted URLs.

emerson / x-stream_enhanced_xegp_firmware+3
Network
Published May 20, 2021
CVE-2021-27465
MEDIUM6.1

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications do not validate webpage input, which could allow an attacker to inject arbitrary HTML code into a webpage. This would allow an attacker to modify the page and display incorrect or undesirable data.

emerson / x-stream_enhanced_xegp_firmware+3
Network
Published May 20, 2021
CVE-2021-27467
MEDIUM6.1

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected product’s web interface allows an attacker to route click or keystroke to another page provided by the attacker to gain unauthorized access to sensitive information.

emerson / x-stream_enhanced_xegp_firmware+3
Network
Published May 20, 2021
CVE-2021-27463
MEDIUM5.3

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications utilize persistent cookies where the session cookie attribute is not properly invalidated, allowing an attacker to intercept the cookies and gain access to sensitive information.

emerson / x-stream_enhanced_xegp_firmware+3
Network
Published May 20, 2021