GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vulnerable to code injection, which may allow an attacker to insert malicious configuration files in the expected web server execution path and gain full control of the HMI software.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2023-03-16T19:13:52.427Z
Updated: 2024-08-02T05:17:50.230Z
Reserved: 2023-01-31T15:52:11.560Z
Link: CVE-2023-0598
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-03-16T20:15:11.327
Modified: 2024-11-21T07:37:27.820
Link: CVE-2023-0598
Redhat
No data.