CVE-2013-0654: Input Validation
CimWebServer in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary commands or cause a denial of service (daemon crash) via a crafted packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0654?
CVE-2013-0654 is considered a high severity vulnerability due to its potential for remote code execution and denial of service.
How do I fix CVE-2013-0654?
To mitigate CVE-2013-0654, it is recommended to apply the latest security patches provided by GE for the affected versions of Proficy HMI/SCADA and Proficy Process Systems.
Which versions are affected by CVE-2013-0654?
CVE-2013-0654 affects GE Intelligent Platforms Proficy HMI/SCADA CIMPLICITY versions 4.01 through 8.0, as well as Proficy Process Systems.
What types of attacks can be performed using CVE-2013-0654?
CVE-2013-0654 can allow remote attackers to execute arbitrary commands or cause a denial of service attack on the affected systems.
Is there a specific workaround for CVE-2013-0654?
Currently, the best workaround for CVE-2013-0654 is to restrict network access to the affected services and ensure that only trusted users can interact with them.