
CVE-2023-4487 – GE Digital CIMPLICITY Process Control
https://notcve.org/view.php?id=CVE-2023-4487
05 Sep 2023 — GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected web server execution path to escalate privileges and gain full control of the HMI software. GE CIMPLICITY 2023 contiene una vulnerabilidad de control de procesos, que podría permitir a un atacante local insertar archivos de configuración maliciosos en la ruta de ejecución esperada del servidor web para escalar privilegios y obtener el control total del software... • https://digitalsupport.ge.com/s/article/GE-Digital-CIMPLICITY-Privilege-Escalation-Vulnerability • CWE-114: Process Control •

CVE-2023-3463 – GE Digital CIMPLICITY Heap-based Buffer Overflow
https://notcve.org/view.php?id=CVE-2023-3463
19 Jul 2023 — All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sources are vulnerable to memory corruption issues due to insufficient input validation, including issues such as out-of-bounds reads and writes, use-after-free, stack-based buffer overflows, uninitialized pointers, and a heap-based buffer overflow. Successful exploitation could allow an attacker to execute arbitrary code. • https://www.cisa.gov/news-events/ics-advisories/icsa-23-199-06 • CWE-122: Heap-based Buffer Overflow CWE-787: Out-of-bounds Write •

CVE-2022-3092 – GE CIMPLICITY Out-of-bounds Write
https://notcve.org/view.php?id=CVE-2022-3092
07 Dec 2022 — GE CIMPICITY versions 2022 and prior is vulnerable to an out-of-bounds write, which could allow an attacker to execute arbitrary code. Las versiones 2022 y anteriores de GE CIMPICITY son vulnerables a una escritura fuera de los límites, lo que podría permitir a un atacante ejecutar código arbitrario. • https://www.cisa.gov/uscert/ics/advisories/icsa-22-326-04 • CWE-787: Out-of-bounds Write •

CVE-2022-3084 – GE CIMPLICITY Access of Uninitialized Pointer
https://notcve.org/view.php?id=CVE-2022-3084
07 Dec 2022 — GE CIMPICITY versions 2022 and prior is vulnerable when data from a faulting address controls code flow starting at gmmiObj!CGmmiRootOptionTable, which could allow an attacker to execute arbitrary code. GE CIMPICITY versiones 2022 y anteriores es vulnerable cuando los datos de una dirección defectuosa controlan el flujo de código a partir de gmmiObj!CGmmiRootOptionTable, lo que podría permitir a un atacante ejecutar código arbitrario. • https://www.cisa.gov/uscert/ics/advisories/icsa-22-326-04 • CWE-824: Access of Uninitialized Pointer •

CVE-2022-2952 – GE CIMPLICITY Access of Uninitialized Pointer
https://notcve.org/view.php?id=CVE-2022-2952
07 Dec 2022 — GE CIMPICITY versions 2022 and prior is vulnerable when data from a faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, which could allow an attacker to execute arbitrary code. GE CIMPICITY versiones 2022 y anteriores es vulnerable cuando los datos de una dirección defectuosa controlan el flujo de código a partir de gmmiObj!CGmmiOptionContainer, lo que podría permitir a un atacante ejecutar código arbitrario. • https://www.cisa.gov/uscert/ics/advisories/icsa-22-326-04 • CWE-824: Access of Uninitialized Pointer •

CVE-2022-2948 – GE CIMPLICITY Heap-based Buffer Overflow
https://notcve.org/view.php?id=CVE-2022-2948
07 Dec 2022 — GE CIMPICITY versions 2022 and prior is vulnerable to a heap-based buffer overflow, which could allow an attacker to execute arbitrary code. Las versiones 2022 y anteriores de GE CIMPICITY son vulnerables a un desbordamiento de búfer de almacenamiento dinámico, lo que podría permitir a un atacante ejecutar código arbitrario. • https://www.cisa.gov/uscert/ics/advisories/icsa-22-326-04 • CWE-122: Heap-based Buffer Overflow •

CVE-2022-2002 – GE CIMPLICITY Untrusted Pointer Dereference
https://notcve.org/view.php?id=CVE-2022-2002
07 Dec 2022 — GE CIMPICITY versions 2022 and prior is vulnerable when data from faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, which could allow an attacker to execute arbitrary code. GE CIMPICITY versiones 2022 y anteriores es vulnerable cuando los datos de la dirección defectuosa controlan el flujo de código que comienza en gmmiObj!CGmmiOptionContainer, lo que podría permitir a un atacante ejecutar código arbitrario. • https://www.cisa.gov/uscert/ics/advisories/icsa-22-326-04 • CWE-822: Untrusted Pointer Dereference •

CVE-2022-21798 – ICSA-22-053-02 GE Proficy CIMPLICITY-Cleartext
https://notcve.org/view.php?id=CVE-2022-21798
25 Feb 2022 — The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which can be easily spoofed and used to log in to make operational changes to the system. El producto afectado es vulnerable debido a una transmisión en texto sin cifrar de las credenciales visualizadas en la red de CIMPLICITY, que pueden ser fácilmente suplantadas y usadas para iniciar sesión y realizar cambios operativos en el sistema. • https://www.cisa.gov/uscert/ics/advisories/icsa-22-053-02 • CWE-319: Cleartext Transmission of Sensitive Information •

CVE-2020-6992
https://notcve.org/view.php?id=CVE-2020-6992
15 Apr 2020 — A local privilege escalation vulnerability has been identified in the GE Digital CIMPLICITY HMI/SCADA product v10.0 and prior. If exploited, this vulnerability could allow an adversary to modify the system, leading to the arbitrary execution of code. This vulnerability is only exploitable if an attacker has access to an authenticated session. GE Digital CIMPLICITY v11.0, released January 2020, contains mitigation for this local privilege escalation vulnerability. GE Digital recommends all users upgrade to G... • https://www.us-cert.gov/ics/advisories/icsa-20-098-02 • CWE-269: Improper Privilege Management •

CVE-2018-15362
https://notcve.org/view.php?id=CVE-2018-15362
07 Dec 2018 — XXE in GE Proficy Cimplicity GDS versions 9.0 R2, 9.5, 10.0 XEE (XML External Entity) en GE Proficy Cimplicity GDS en versiones 9.0 R2, 9.5 y 10.0. • http://www.securityfocus.com/bid/106133 • CWE-611: Improper Restriction of XML External Entity Reference •