Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Roman Dvorkin

Researcher fromOTORIO
#17594of 53,633
15.3Total CVSS
Vulnerabilities · 2
High
2
PT-2022-16337
7.8
2022-02-25
Ge · Ge Cimpicity · CVE-2022-23921
**Name of the Vulnerable Software and Affected Versions** GE CIMPLICITY (affected versions not specified) **Description** Exploitation of this issue may result in local privilege escalation and code execution. It is noted that exploitation is only possible if the attacker has login access to a machine actively running CIMPLICITY, the CIMPLICITY server is not already running a project, and the server is licensed for multiple projects. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2022-1872
7.5
2022-01-27
Ge Digital · Proficy Hmi/Scada - Cimplicity · CVE-2022-21798
**Name of the Vulnerable Software and Affected Versions** Proficy HMI/SCADA CIMPLICITY (affected versions not specified) **Description** The issue is related to the transmission of data in cleartext, which can be exploited to conduct spoofing attacks. This cleartext transmission of credentials in the CIMPLICITY network can be easily intercepted and used to log in to the system, allowing an attacker to make operational changes. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.