Skip to main content

Vendor/product archive

ge / cimplicity CVEs

Beta · best-effort

12 CVEs tagged to ge / cimplicity1 Critical, 7 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2023-4487

Published Sep 5, 2023

GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected web server execution path to e…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3463

Published Jul 19, 2023

All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sources are vulnerable to memory corruption issues due to insuff…

CVSS 6.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-3092

Published Dec 8, 2022

GE CIMPICITY versions 2022 and prior is vulnerable to an out-of-bounds write, which could allow an attacker to execute arbitrary code.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3084

Published Dec 8, 2022

GE CIMPICITY versions 2022 and prior is vulnerable when data from a faulting address controls code flow starting at gmmiObj!CGmmiRootOptionTable, which could allow an attacker to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2952

Published Dec 7, 2022

GE CIMPICITY versions 2022 and prior is vulnerable when data from a faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, which could allow an attacker t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2948

Published Dec 7, 2022

GE CIMPICITY versions 2022 and prior is vulnerable to a heap-based buffer overflow, which could allow an attacker to execute arbitrary code.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2002

Published Dec 7, 2022

GE CIMPICITY versions 2022 and prior is vulnerable when data from faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, which could allow an attacker t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-21798

Published Feb 25, 2022

The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which can be easily spoofed and used to log in to make operational…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-6992

Published Apr 15, 2020

A local privilege escalation vulnerability has been identified in the GE Digital CIMPLICITY HMI/SCADA product v10.0 and prior. If exploited, this vulnerability could allow an adve…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9360

Published Feb 13, 2017

An issue was discovered in General Electric (GE) Proficy HMI/SCADA iFIX Version 5.8 SIM 13 and prior versions, Proficy HMI/SCADA CIMPLICITY Version 9.0 and prior versions, and Pro…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5787

Published Jul 15, 2016

General Electric (GE) Digital Proficy HMI/SCADA - CIMPLICITY before 8.2 SIM 27 mishandles service DACLs, which allows local users to modify a service configuration via unspecified…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1