CVE-2019-18243: Medium severity ge digital proficy ifix 2022 vulnerability
HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through the registry. This may allow privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-18243.
What is the title of the vulnerability?
The title of the vulnerability is HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through the registry.
What is the severity of CVE-2019-18243?
The severity of CVE-2019-18243 is medium with a severity value of 5.5.
How does CVE-2019-18243 affect the affected software?
CVE-2019-18243 affects GE iFIX versions 6.1 and prior, allowing a local authenticated user to modify system-wide iFIX configurations through the registry.
How can the privilege escalation vulnerability in CVE-2019-18243 be fixed?
To fix the privilege escalation vulnerability in CVE-2019-18243, it is recommended to upgrade to a version of GE iFIX that is not affected by the vulnerability.