CVE-2014-2355: GE Proficy HMI/SCADA CIMPLICITY CimView
Published Jan 17, 2015
·Updated
The (1) CimView and (2) CimEdit components in GE Proficy HMI/SCADA-CIMPLICITY 8.2 and earlier allow remote attackers to gain privileges via a crafted CIMPLICITY screen (aka .CIM) file.
Affected Software
1 affected component
GE Intelligent Platforms Proficy Hmi\/scada Cimplicity<=8.2
Remediation
Information
GE recommends that asset owners apply product updates to Proficy
HMI/SCADA–CIMPLICITY Versions 8.1 and 8.2. The following product updates
address the memory access violation vulnerability:
Proficy HMI/SCADA – CIMPLICITY 8.1 SIM 29 (DN4219) available at: http://support.ge-ip.com/support/index?page=dwchannel&id=DN4219
Proficy HMI/SCADA–CIMPLICITY 8.2 SIM 26 (DN4197) available at: http://support.ge-ip.com/support/index?page=dwchannel&id=DN4197
Event History
Jan 17, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2355?
CVE-2014-2355 is classified as a high-severity vulnerability due to its potential to allow remote privilege escalation.
2
How do I fix CVE-2014-2355?
To mitigate CVE-2014-2355, users should upgrade to a version of GE Proficy HMI/SCADA-CIMPLICITY later than 8.2.
3
Can CVE-2014-2355 be exploited remotely?
Yes, CVE-2014-2355 can be exploited remotely through a maliciously crafted CIMPLICITY screen file.
4
Which components are affected by CVE-2014-2355?
The affected components of CVE-2014-2355 are CimView and CimEdit in GE Proficy HMI/SCADA-CIMPLICITY.
5
What type of vulnerability is CVE-2014-2355?
CVE-2014-2355 is a privilege escalation vulnerability.