An issue was discovered in General Electric (GE) Proficy HMI/SCADA iFIX Version 5.8 SIM 13 and prior versions, Proficy HMI/SCADA CIMPLICITY Version 9.0 and prior versions, and Proficy Historian Version 6.0 and prior versions. An attacker may be able to retrieve user passwords if he or she has access to an authenticated session.
📦
cimplicity
Vendor: ge
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
6
Remote Access
Total CVEs
31
Total Indexed
Avg. EPSS
1.09%
Exploit Prob.
Security Vulnerability Index
Page 2 / 4
6.7
CVSS
Severity: MEDIUM
6.3
CVSS
General Electric (GE) Digital Proficy HMI/SCADA - CIMPLICITY before 8.2 SIM 27 mishandles service DACLs, which allows local users to modify a service configuration via unspecified vectors.
Severity: MEDIUM
10.0
CVSS
Heap-based buffer overflow in w32rtr.exe in GE Fanuc CIMPLICITY HMI SCADA system 7.0 before 7.0 SIM 9, and earlier versions before 6.1 SP6 Hot fix - 010708_162517_6106, allow remote attackers to execute arbitrary code via unknown vectors.
Severity: HIGH