First published: Tue Jan 17 2023(Updated: )
An unauthorized user could possibly delete any file on the system.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Ge Proficy Historian | >=7.0<2023 | |
GE Digital Proficy Historian v7.0 and higher versions |
GE Digital released Proficy Historian 2023 https://www.ge.com/digital/applications/proficy-historian to mitigate these vulnerabilities. SIMs have also been released for all affected versions.Users can find out more about the vulnerabilities, how to obtain, and install the updates by visiting this notification document from GE Digital https://digitalsupport.ge.com/s/article/GE-Digital-Product-Security-Advisory-GED-23-01 .
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-46331 is high (8.1).
An unauthorized user can delete any file on the system by exploiting the vulnerability (CVE-2022-46331).
The Ge Proficy Historian software version 7.0 up to 2023 is affected by CVE-2022-46331.
You can find more information about CVE-2022-46331 in the GE Digital Product Security Advisory (GED-23-01) and the CISA ICS Advisory (ICSA-23-017-01).
The Common Weakness Enumeration (CWE) ID for CVE-2022-46331 is CWE-284.