PT-2015-3317 · General Electric · Proficy Hmi/Scada - Cimplicity+2

Ilya Karpov

·

Published

2015-08-05

·

Updated

2022-02-03

·

CVE-2016-9360

CVSS v3.1

6.7

Medium

VectorAV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions General Electric (GE) Proficy HMI/SCADA iFIX versions 5.8 SIM 13 and prior General Electric (GE) Proficy HMI/SCADA CIMPLICITY versions 9.0 and prior General Electric (GE) Proficy Historian versions 6.0 and prior
Description The issue allows an attacker to retrieve user passwords if they have access to an authenticated session. This is due to insufficient protection of user accounts. An attacker with local access may exploit this to learn user passwords.
Recommendations For General Electric (GE) Proficy HMI/SCADA iFIX versions 5.8 SIM 13 and prior, update to a version later than 5.8 SIM 13 to resolve the issue. For General Electric (GE) Proficy HMI/SCADA CIMPLICITY versions 9.0 and prior, update to a version later than 9.0 to resolve the issue. For General Electric (GE) Proficy Historian versions 6.0 and prior, update to a version later than 6.0 to resolve the issue. As a temporary workaround, consider restricting access to authenticated sessions to minimize the risk of exploitation.

Fix

Insufficiently Protected Credentials

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02216
CVE-2016-9360

Affected Products

Proficy Hmi/Scada - Cimplicity
Proficy Hmi/Scada Ifix
Proficy Historian