CVE-2019-18255: Medium severity ge digital proficy ifix 2022 vulnerability
Published Feb 18, 2021
·Updated
HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through section objects. This may allow privilege escalation.
Affected Software
2 affected components
GE Digital HMI/SCADA iFIX<=6.1
GE iFIX<=6.1
Event History
Feb 18, 2021
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-18255.
2
What is the severity of CVE-2019-18255?
CVE-2019-18255 has a severity score of 5.5, which is considered medium.
3
What software versions are affected by CVE-2019-18255?
CVE-2019-18255 affects HMI/SCADA iFIX versions 6.1 and prior.
4
How can a local authenticated user exploit CVE-2019-18255?
A local authenticated user can exploit CVE-2019-18255 to modify system-wide iFIX configurations through section objects, potentially leading to privilege escalation.
5
Is there a fix available for CVE-2019-18255?
At the time of this writing, there is no known fix available for CVE-2019-18255. It is recommended to follow the suggestions provided in the referenced advisory to mitigate the risk.