GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected web server execution path to escalate privileges and gain full control of the HMI software.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54342 | GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected web server execution path to escalate privileges and gain full control of the HMI software. |
Solution
GE Digital recommends users apply the following mitigations: * Update CIMPLICITY to v2023 SIM 1 https://digitalsupport.ge.com/s/article/CIMPLICITY-2023-SIM-1 (login is required) Please refer to GE Digital’s security bulletin https://digitalsupport.ge.com/s/article/GE-Digital-CIMPLICITY-Privilege-Escalation-Vulnerability (login is required) for more information.
Workaround
No workaround given by the vendor.
Thu, 16 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-16T21:30:31.371Z
Reserved: 2023-08-22T20:32:42.621Z
Link: CVE-2023-4487
Updated: 2024-08-02T07:31:05.481Z
Status : Modified
Published: 2023-09-05T23:15:08.177
Modified: 2024-11-21T08:35:16.153
Link: CVE-2023-4487
No data.
OpenCVE Enrichment
No data.
EUVD