An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.









Advisories
Source ID Title
EUVD EUVD EUVD-2022-41052 An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.
Fixes

Solution

GE Digital released Proficy Historian 2023 https://www.ge.com/digital/applications/proficy-historian  to mitigate these vulnerabilities.  SIMs have also been released for all affected versions.Users can find out more about the vulnerabilities, how to obtain, and install the updates by visiting this notification document from GE Digital https://digitalsupport.ge.com/s/article/GE-Digital-Product-Security-Advisory-GED-23-01 .  


Workaround

No workaround given by the vendor.

History

Thu, 16 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T22:00:41.329Z

Reserved: 2022-12-15T18:53:06.212Z

Link: CVE-2022-38469

cve-icon Vulnrichment

Updated: 2024-08-03T10:54:03.672Z

cve-icon NVD

Status : Modified

Published: 2023-01-18T00:15:11.897

Modified: 2024-11-21T07:16:32.490

Link: CVE-2022-38469

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.