Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Roman Dvorkin

Researcher fromOTORIO
#18714of 56,336
15.3Total CVSS
Vulnerabilities · 2
High
2
PT-2022-16337
7.8
2022-02-25
Ge · Ge Cimpicity · CVE-2022-23921
**Name of the Vulnerable Software and Affected Versions** GE CIMPLICITY (affected versions not specified) **Description** Exploitation of this issue may result in local privilege escalation and code execution. It is noted that exploitation is only possible if the attacker has login access to a machine actively running CIMPLICITY, the CIMPLICITY server is not already running a project, and the server is licensed for multiple projects. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2022-1872
7.5
2022-01-27
Ge Digital · Proficy Hmi/Scada - Cimplicity · CVE-2022-21798
**Name of the Vulnerable Software and Affected Versions** Proficy HMI/SCADA CIMPLICITY (affected versions not specified) **Description** The issue is related to the transmission of data in cleartext, which can be exploited to conduct spoofing attacks. This cleartext transmission of credentials in the CIMPLICITY network can be easily intercepted and used to log in to the system, allowing an attacker to make operational changes. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.