GE Proficy HMI/SCADA CIMPLICITY CimView
Summary
| CVE | CVE-2014-2355 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-01-17 02:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The (1) CimView and (2) CimEdit components in GE Proficy HMI/SCADA-CIMPLICITY 8.2 and earlier allow remote attackers to gain privileges via a crafted CIMPLICITY screen (aka .CIM) file. |
Risk And Classification
Primary CVSS: v2.0 6.9 from [email protected]
AV:L/AC:M/Au:N/C:C/I:C/A:C
Problem Types: CWE-119 | CWE-119 CWE-119
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 6.9 | AV:L/AC:M/Au:N/C:C/I:C/A:C | |
| 2.0 | [email protected] | Secondary | 6.6 | AV:L/AC:M/Au:S/C:C/I:C/A:C | |
| 2.0 | CNA | CVSS | 6.6 | AV:L/AC:M/Au:S/C:C/I:C/A:C |
CVSS v2.0 Breakdown
AV:L/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ge | Intelligent Platforms Proficy Hmi/scada Cimplicity | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | GE | Proficy HMI/SCADACIMPLICITY | affected 8.2 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GE Proficy HMI/SCADA CIMPLICITY CimView Memory Access Violation | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| www.cisa.gov/news-events/ics-advisories/icsa-14-289-02 | [email protected] | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Said Arfi (en)
Additional Advisory Data
Solutions
CNA: GE recommends that asset owners apply product updates to Proficy HMI/SCADA–CIMPLICITY Versions 8.1 and 8.2. The following product updates address the memory access violation vulnerability: Proficy HMI/SCADA – CIMPLICITY 8.1 SIM 29 (DN4219) available at: http://support.ge-ip.com/support/index?page=dwchannel&id=DN4219 Proficy HMI/SCADA–CIMPLICITY 8.2 SIM 26 (DN4197) available at: http://support.ge-ip.com/support/index?page=dwchannel&id=DN4197
Workarounds
CNA: In cases where upgrading is not feasible, GE advises asset owners using CIMPLICITY versions prior to 8.1 to consider using the following recommendations that may mitigate or eliminate the impact of the vulnerability: * Take steps to properly secure and protect stored CIMPLICITY screen files (.CIM). * Avoid using .CIM files received from unknown sources. * Avoid sending unprotected .CIM files over unencrypted networks or public Internet. * Consider using a strong hashing algorithm to validate integrity of created .CIM files and ensure they have not been tampered with over time.