GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected web server execution path to escalate privileges and gain full control of the HMI software.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-54342 GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected web server execution path to escalate privileges and gain full control of the HMI software.
Fixes

Solution

​GE Digital recommends users apply the following mitigations: * ​Update CIMPLICITY to v2023 SIM 1 https://digitalsupport.ge.com/s/article/CIMPLICITY-2023-SIM-1  (login is required) ​Please refer to GE Digital’s security bulletin https://digitalsupport.ge.com/s/article/GE-Digital-CIMPLICITY-Privilege-Escalation-Vulnerability  (login is required) for more information.


Workaround

No workaround given by the vendor.

History

Thu, 16 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T21:30:31.371Z

Reserved: 2023-08-22T20:32:42.621Z

Link: CVE-2023-4487

cve-icon Vulnrichment

Updated: 2024-08-02T07:31:05.481Z

cve-icon NVD

Status : Modified

Published: 2023-09-05T23:15:08.177

Modified: 2024-11-21T08:35:16.153

Link: CVE-2023-4487

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.