CVE-2022-23921: ICSA-22-053-01 GE Proficy CIMPLICITY-IPM
Exploitation of this vulnerability may result in local privilege escalation and code execution. GE maintains exploitation of this vulnerability is only possible if the attacker has login access to a machine actively running CIMPLICITY, the CIMPLICITY server is not already running a project, and the server is licensed for multiple projects.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-23921.
What is the severity of CVE-2022-23921?
The severity of CVE-2022-23921 is high (7.8).
What is the affected software of CVE-2022-23921?
The affected software of CVE-2022-23921 is GE Proficy Cimplicitiy version 11.1.
What are the potential consequences of CVE-2022-23921?
Exploitation of CVE-2022-23921 may result in local privilege escalation and code execution.
How can CVE-2022-23921 be exploited?
CVE-2022-23921 can be exploited if the attacker has login access to a machine actively running CIMPLICITY, the CIMPLICITY server is not already running a project, and the system environment supports code execution.