Description




An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.









Published: 2023-01-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

GE Digital released Proficy Historian 2023 https://www.ge.com/digital/applications/proficy-historian  to mitigate these vulnerabilities.  SIMs have also been released for all affected versions.Users can find out more about the vulnerabilities, how to obtain, and install the updates by visiting this notification document from GE Digital https://digitalsupport.ge.com/s/article/GE-Digital-Product-Security-Advisory-GED-23-01 .  

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-41052 An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.
History

Thu, 16 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Ge Proficy Historian
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T22:00:41.329Z

Reserved: 2022-12-15T18:53:06.212Z

Link: CVE-2022-38469

cve-icon Vulnrichment

Updated: 2024-08-03T10:54:03.672Z

cve-icon NVD

Status : Modified

Published: 2023-01-18T00:15:11.897

Modified: 2024-11-21T07:16:32.490

Link: CVE-2022-38469

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses