CVE-2022-21798
Summary
| CVE | CVE-2022-21798 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-25 19:15:00 UTC |
| Updated | 2022-03-08 15:38:00 UTC |
| Description | The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which can be easily spoofed and used to log in to make operational changes to the system. |
Risk And Classification
Problem Types: CWE-319
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ge | Cimplicity | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GE Proficy CIMPLICITY-Cleartext | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Yuval Ardon and Roman Dvorkin of OTORIO reported this vulnerability to CISA
Legacy QID Mappings
- 591234 GE Proficy CIMPLICITY Sensitive Information Disclosure Vulnerability (ICSA-22-053-02)