First published: Tue Sep 05 2023(Updated: )
GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected web server execution path to escalate privileges and gain full control of the HMI software.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
GE CIMPLICITY | =2023 | |
GE Digital CIMPLICITY | =2023 |
GE Digital recommends users apply the following mitigations: * Update CIMPLICITY to v2023 SIM 1 https://digitalsupport.ge.com/s/article/CIMPLICITY-2023-SIM-1 (login is required) Please refer to GE Digital’s security bulletin https://digitalsupport.ge.com/s/article/GE-Digital-CIMPLICITY-Privilege-Escalation-Vulnerability (login is required) for more information.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID is CVE-2023-4487.
The title of the vulnerability is 'GE CIMPLICITY 2023 Process Control Vulnerability'.
The severity of this vulnerability is high with a CVSS score of 7.8.
This vulnerability allows a local attacker to insert malicious configuration files in the expected web server execution path of GE CIMPLICITY 2023, escalating privileges and gaining full control of the HMI software.
To fix this vulnerability, it is recommended to apply the latest security patches and updates provided by GE.