CVE-2022-21798: ICSA-22-053-02 GE Proficy CIMPLICITY-Cleartext
The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which can be easily spoofed and used to log in to make operational changes to the system.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-21798?
CVE-2022-21798 is a vulnerability in the GE CIMPLICITY software that allows for cleartext transmission of credentials, potentially allowing unauthorized users to log in and make operational changes.
How severe is CVE-2022-21798?
CVE-2022-21798 has a severity rating of 9.8, which is classified as critical.
What is the affected software for CVE-2022-21798?
The affected software for CVE-2022-21798 is GE CIMPLICITY.
How can CVE-2022-21798 be exploited?
CVE-2022-21798 can be exploited by intercepting cleartext credentials transmitted over the CIMPLICITY network and using them to log in and make unauthorized changes to the system.
Is there a fix for CVE-2022-21798?
To fix CVE-2022-21798, users should apply the latest security patches or updates provided by GE for the CIMPLICITY software.