VendorsGEcimplicityall versions
Vulnerabilities

GE neral Electric Cimplicity

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2022-21798
ICSA-22-053-02 GE Proficy CIMPLICITY-Cleartext
Published 2022-02-25 · Modified
9.8EPSS 0.006
CVE-2023-3463
GE Digital CIMPLICITY Heap-based Buffer Overflow
Published 2023-07-19 · Modified
9.8EPSS 0.004
CVE-2018-15362
XXE in GE Proficy Cimplicity GDS versions 9.0 R2, 9.5, 10.0
Published 2018-12-07 · Modified
9.1EPSS 0.027
CVE-2022-2002
GE CIMPLICITY Untrusted Pointer Dereference
Published 2022-12-07 · Modified
7.8EPSS 0.003
CVE-2022-2948
GE CIMPLICITY Heap-based Buffer Overflow
Published 2022-12-07 · Modified
7.8EPSS 0.003
CVE-2022-2952
GE CIMPLICITY Access of Uninitialized Pointer
Published 2022-12-07 · Modified
7.8EPSS 0.002
CVE-2022-3084
GE CIMPLICITY Access of Uninitialized Pointer
Published 2022-12-07 · Modified
7.8EPSS 0.002
CVE-2022-3092
GE CIMPLICITY Out-of-bounds Write
Published 2022-12-07 · Modified
7.8EPSS 0.002
CVE-2023-4487
GE Digital CIMPLICITY Process Control
Published 2023-09-05 · Modified
7.8EPSS 0.002
CVE-2020-6992
A local privilege escalation vulnerability has been identified in the GE Digital CIMPLICITY HMI/SCADA product v10.0 and prior. If exploited, this vulnerability could allow an adversary to modify the system, leading to the arbitrary execution of code. This vulnerability is only exploitable if an attacker has access to an authenticated session. GE Digital CIMPLICITY v11.0, released January 2020, contains mitigation for this local privilege escalation vulnerability. GE Digital recommends all users upgrade to GE CIMPLICITY v11.0 or newer.
Published 2020-04-15 · Modified
6.7EPSS 0.004
CVE-2016-9360
An issue was discovered in General Electric (GE) Proficy HMI/SCADA iFIX Version 5.8 SIM 13 and prior versions, Proficy HMI/SCADA CIMPLICITY Version 9.0 and prior versions, and Proficy Historian Version 6.0 and prior versions. An attacker may be able to retrieve user passwords if he or she has access to an authenticated session.
Published 2017-02-13 · Modified
6.7EPSS 0.004
CVE-2016-5787
General Electric (GE) Digital Proficy HMI/SCADA - CIMPLICITY before 8.2 SIM 27 mishandles service DACLs, which allows local users to modify a service configuration via unspecified vectors.
Published 2016-07-15 · Modified
6.3EPSS 0.004