CVE-2014-0750: GE Proficy HMI/SCADA Path Traversal
Directory traversal vulnerability in gefebt.exe in the WebView CimWeb components in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY through 8.2 SIM 24, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary code via a crafted HTTP request, aka ZDI-CAN-1622.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY (WebView CimWeb components) through 8.2 SIM 24to a version that resolves this vulnerability.Patch ZDI-CAN-1622 - Remove
Remove
gefebt.exefrom your environment.Delete or move all copies of the gefebt.exe files that are accessible from a Web client (to mitigate the directory traversal/remote code execution vulnerability).
- Compensating control
If the production Web configuration currently relies on gefebt.exe, make the configuration changes described in the GE Product Security Advisory for this vulnerability (GEIP13-05 and/or GEIP13-06) so the Web server no longer exposes the affected component via Web pages.
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0750?
CVE-2014-0750 is rated as critical due to the potential for remote code execution.
How do I fix CVE-2014-0750?
To mitigate CVE-2014-0750, upgrade to a version of GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY that addresses the vulnerability.
What software versions are affected by CVE-2014-0750?
CVE-2014-0750 affects multiple versions including Proficy HMI/SCADA - CIMPLICITY versions up to and including 8.2 SIM 24.
Who can exploit the vulnerability identified by CVE-2014-0750?
Remote attackers can exploit CVE-2014-0750 by sending a crafted HTTP request.
What types of attacks can be executed through CVE-2014-0750?
CVE-2014-0750 allows for arbitrary code execution, potentially leading to full system compromise.