PT-2015-3317 · General Electric · Proficy Hmi/Scada - Cimplicity+2
Ilya Karpov
·
Published
2015-08-05
·
Updated
2022-02-03
·
CVE-2016-9360
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
General Electric (GE) Proficy HMI/SCADA iFIX versions 5.8 SIM 13 and prior
General Electric (GE) Proficy HMI/SCADA CIMPLICITY versions 9.0 and prior
General Electric (GE) Proficy Historian versions 6.0 and prior
Description
The issue allows an attacker to retrieve user passwords if they have access to an authenticated session. This is due to insufficient protection of user accounts. An attacker with local access may exploit this to learn user passwords.
Recommendations
For General Electric (GE) Proficy HMI/SCADA iFIX versions 5.8 SIM 13 and prior, update to a version later than 5.8 SIM 13 to resolve the issue.
For General Electric (GE) Proficy HMI/SCADA CIMPLICITY versions 9.0 and prior, update to a version later than 9.0 to resolve the issue.
For General Electric (GE) Proficy Historian versions 6.0 and prior, update to a version later than 6.0 to resolve the issue.
As a temporary workaround, consider restricting access to authenticated sessions to minimize the risk of exploitation.
Fix
Insufficiently Protected Credentials
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Proficy Hmi/Scada - Cimplicity
Proficy Hmi/Scada Ifix
Proficy Historian