First published: Thu Feb 18 2021(Updated: )
HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through the registry. This may allow privilege escalation.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
GE iFIX | <=6.1 | |
GE Digital HMI/SCADA iFIX | <=6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-18243.
The title of the vulnerability is HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through the registry.
The severity of CVE-2019-18243 is medium with a severity value of 5.5.
CVE-2019-18243 affects GE iFIX versions 6.1 and prior, allowing a local authenticated user to modify system-wide iFIX configurations through the registry.
To fix the privilege escalation vulnerability in CVE-2019-18243, it is recommended to upgrade to a version of GE iFIX that is not affected by the vulnerability.