First published: Tue Jan 17 2023(Updated: )
Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication status.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Ge Proficy Historian | >=7.0<2023 | |
GE Digital Proficy Historian v7.0 and higher versions |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-46732 is a vulnerability in Ge Proficy Historian software that allows an attacker to execute commands even if authentication fails.
CVE-2022-46732 has a severity score of 9.8 out of 10, which indicates it is critical.
Ge Proficy Historian version 7.0 to 2023 is affected by CVE-2022-46732.
There is currently no patch or fix available for CVE-2022-46732. It is recommended to implement network segmentation and other security measures to mitigate the risk.
You can find more information about CVE-2022-46732 on the GE Digital Product Security Advisory and the CISA website.