CVE-2022-46732: Critical severity ge proficy historian vulnerability
Published Jan 17, 2023
·Updated
Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication status.
Affected Software
2 affected components
GE Digital Proficy Historian v7.0 and higher versions
GE Proficy Historian>=7.0<2023
Event History
Jan 17, 2023
CVE Published
via MITRE·11:31 PM
Data Sourced
via MITRE·11:31 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-46732?
CVE-2022-46732 is a vulnerability in Ge Proficy Historian software that allows an attacker to execute commands even if authentication fails.
2
How severe is CVE-2022-46732?
CVE-2022-46732 has a severity score of 9.8 out of 10, which indicates it is critical.
3
What software is affected by CVE-2022-46732?
Ge Proficy Historian version 7.0 to 2023 is affected by CVE-2022-46732.
4
How can I fix CVE-2022-46732?
There is currently no patch or fix available for CVE-2022-46732. It is recommended to implement network segmentation and other security measures to mitigate the risk.
5
Where can I find more information about CVE-2022-46732?
You can find more information about CVE-2022-46732 on the GE Digital Product Security Advisory and the CISA website.