CVE-2013-2785
GE Proficy CIMPLICITY CimWebServer Broadcase/Init Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple buffer overflows in CimWebServer.exe in the WebView component in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY before 8.0 SIM 27, 8.1 before SIM 25, and 8.2 before SIM 19, and Proficy Process Systems with CIMPLICITY, allow remote attackers to execute arbitrary code via crafted data in packets to TCP port 10212, aka ZDI-CAN-1621 and ZDI-CAN-1624.
Múltiples vulnerabilidades de desbordamiento de búfer en GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY anterior a 8.0 SIM 27, 8.1 anterior a SIM 25, y 8.2 anterior a SIM 19, y Proficy Process Systems con CIMPLICITY, permite a atacantes remotos la ejecución de código arbitrario a través de datos manipulados en paquetes TCP hacia el puerto 10212. Aka ZDI-CAN-1621 y ZDI-CAN-1624.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of GE Proficy CIMPLICITY. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CimWebServer component. This component performs insufficient bounds checking on user-supplied data passed in the szOptions field which results in stack corruption. An attacker can leverage this situation to execute code under the context of the process.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-04-11 CVE Reserved
- 2013-07-26 CVE Published
- 2024-09-16 CVE Updated
- 2024-10-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://ics-cert.us-cert.gov/advisories/ICSA-13-170-01 | Us Government Resource | |
http://support.ge-ip.com/support/index?page=kbchannel&id=KB15602 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ge Search vendor "Ge" | Intelligent Platforms Proficy Hmi\/scada Cimplicity Search vendor "Ge" for product "Intelligent Platforms Proficy Hmi\/scada Cimplicity" | 8.0 Search vendor "Ge" for product "Intelligent Platforms Proficy Hmi\/scada Cimplicity" and version "8.0" | - |
Affected
| ||||||
Ge Search vendor "Ge" | Intelligent Platforms Proficy Hmi\/scada Cimplicity Search vendor "Ge" for product "Intelligent Platforms Proficy Hmi\/scada Cimplicity" | 8.1 Search vendor "Ge" for product "Intelligent Platforms Proficy Hmi\/scada Cimplicity" and version "8.1" | - |
Affected
| ||||||
Ge Search vendor "Ge" | Intelligent Platforms Proficy Hmi\/scada Cimplicity Search vendor "Ge" for product "Intelligent Platforms Proficy Hmi\/scada Cimplicity" | 8.2 Search vendor "Ge" for product "Intelligent Platforms Proficy Hmi\/scada Cimplicity" and version "8.2" | - |
Affected
| ||||||
Ge Search vendor "Ge" | Intelligent Platforms Proficy Process Systems With Cimplicity Search vendor "Ge" for product "Intelligent Platforms Proficy Process Systems With Cimplicity" | - | - |
Affected
|