First published: Sat Jan 17 2015(Updated: )
The (1) CimView and (2) CimEdit components in GE Proficy HMI/SCADA-CIMPLICITY 8.2 and earlier allow remote attackers to gain privileges via a crafted CIMPLICITY screen (aka .CIM) file.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
GE Intelligent Platforms Proficy HMI/SCADA CIMPLICITY | <=8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2355 is classified as a high-severity vulnerability due to its potential to allow remote privilege escalation.
To mitigate CVE-2014-2355, users should upgrade to a version of GE Proficy HMI/SCADA-CIMPLICITY later than 8.2.
Yes, CVE-2014-2355 can be exploited remotely through a maliciously crafted CIMPLICITY screen file.
The affected components of CVE-2014-2355 are CimView and CimEdit in GE Proficy HMI/SCADA-CIMPLICITY.
CVE-2014-2355 is a privilege escalation vulnerability.