GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected web server execution path to escalate privileges and gain full control of the HMI software.
Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2023-54342 | GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected web server execution path to escalate privileges and gain full control of the HMI software. | 
Solution
GE Digital recommends users apply the following mitigations: * Update CIMPLICITY to v2023 SIM 1 https://digitalsupport.ge.com/s/article/CIMPLICITY-2023-SIM-1 (login is required) Please refer to GE Digital’s security bulletin https://digitalsupport.ge.com/s/article/GE-Digital-CIMPLICITY-Privilege-Escalation-Vulnerability (login is required) for more information.
Workaround
No workaround given by the vendor.
Thu, 16 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-16T21:30:31.371Z
Reserved: 2023-08-22T20:32:42.621Z
Link: CVE-2023-4487
Updated: 2024-08-02T07:31:05.481Z
Status : Modified
Published: 2023-09-05T23:15:08.177
Modified: 2024-11-21T08:35:16.153
Link: CVE-2023-4487
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD