PT-2023-5230 · Ge · Ge Cimpicity

·

CVE-2023-4487

·

Publicado

2023-09-05

·

Atualizado

2024-01-01

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GE CIMPLICITY version 2023
Description The issue is related to a process control vulnerability in GE CIMPLICITY 2023, which could allow a local attacker to insert malicious configuration files in the expected web server execution path to escalate privileges and gain full control of the HMI software. This vulnerability exists due to a problem with process management.
Recommendations For GE CIMPLICITY version 2023, as a temporary workaround, consider restricting access to the web server execution path to minimize the risk of exploitation. Additionally, monitor the system for any suspicious activity and apply patches as soon as they become available from the vendor. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-05842
CVE-2023-4487

Produtos afetados

Ge Cimpicity