CVE-2022-23921
ICSA-22-053-01 GE Proficy CIMPLICITY-IPM
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Exploitation of this vulnerability may result in local privilege escalation and code execution. GE maintains exploitation of this vulnerability is only possible if the attacker has login access to a machine actively running CIMPLICITY, the CIMPLICITY server is not already running a project, and the server is licensed for multiple projects.
Una explotación de esta vulnerabilidad puede resultar en una escalada local de privilegios y una ejecución de código. GE mantiene que la explotación de esta vulnerabilidad sólo es posible si el atacante presenta acceso a una máquina que ejecuta activamente CIMPLICITY, el servidor de CIMPLICITY no está ejecutando ya un proyecto, y el servidor presenta licencia para múltiples proyectos.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-01-27 CVE Reserved
- 2022-02-25 CVE Published
- 2024-09-17 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-269: Improper Privilege Management
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-053-01 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ge Search vendor "Ge" | Proficy Cimplicitiy Search vendor "Ge" for product "Proficy Cimplicitiy" | <= 11.1 Search vendor "Ge" for product "Proficy Cimplicitiy" and version " <= 11.1" | - |
Affected
|