📦

proficy

Vendor: geautomation

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 1 Remote Access
Total CVEs 1 Total Indexed
Avg. EPSS 0.80% Exploit Prob.
Latest CVE CVE-2022-2791 Nov 22

Security Vulnerability Index

Page 1 / 1
5.9 CVSS

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File with Dangerous Type, and will upload any file written into the PLC logic folder to the connected PLC.

EPSS: 0.18%
7.5 CVSS

Emerson GE Automation Proficy Machine Edition 8.0 allows an access violation and application crash via crafted traffic from a remote device, as demonstrated by an RX7i device.

EPSS: 1.41%