{"api_version":"1","generated_at":"2026-04-23T04:11:33+00:00","cve":"CVE-2023-3463","urls":{"html":"https://cve.report/CVE-2023-3463","api":"https://cve.report/api/cve/CVE-2023-3463.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-3463","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-3463"},"summary":{"title":"CVE-2023-3463","description":"All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sources are vulnerable to memory corruption issues due to insufficient input validation, including issues such as out-of-bounds reads and writes, use-after-free, stack-based buffer overflows, uninitialized pointers, and a heap-based buffer overflow. Successful exploitation could allow an attacker to execute arbitrary code.","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2023-07-19 14:15:00","updated_at":"2023-07-28 13:47:00"},"problem_types":["CWE-787"],"metrics":[],"references":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-23-199-06","name":"https://www.cisa.gov/news-events/ics-advisories/icsa-23-199-06","refsource":"MISC","tags":[],"title":"GE Digital CIMPLICITY | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-3463","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-3463","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"3463","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ge","cpe5":"cimplicity","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-3463","ASSIGNER":"ics-cert@hq.dhs.gov","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"\nAll versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sources are vulnerable to memory corruption issues due to insufficient input validation, including issues such as out-of-bounds reads and writes, use-after-free, stack-based buffer overflows, uninitialized pointers, and a heap-based buffer overflow. Successful exploitation could allow an attacker to execute arbitrary code.\n\n"}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-122 Heap-based Buffer Overflow","cweId":"CWE-122"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"GE Digital","product":{"product_data":[{"product_name":"CIMPLICITY","version":{"version_data":[{"version_affected":"=","version_value":"All"}]}}]}}]}},"references":{"reference_data":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-23-199-06","refsource":"MISC","name":"https://www.cisa.gov/news-events/ics-advisories/icsa-23-199-06"}]},"generator":{"engine":"Vulnogram 0.1.0-dev"},"source":{"advisory":"ICSA-23-199-06","discovery":"EXTERNAL"},"solution":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"\n\n<p>To obtain the latest versions of GE CIMPLICITY, contact your local GE Digital representative at <a target=\"_blank\" rel=\"nofollow\" href=\"https://digitalsupport.ge.com/s/contactsupport\">https://digitalsupport.ge.com/s/contactsupport</a>.</p><p>Exploit is only possible if an authenticated user with local access to the system obtains and opens a document from a malicious source so secure deployment and strong access management by users is essential. GE Digital and customers have a shared responsibility for security and users are required to adhere to the most recent <a target=\"_blank\" rel=\"nofollow\" href=\"https://digitalsupport.ge.com/s/article/CIMPLICITY-Secure-Deployment-Guide2?language=en_US\">Secure Deployment Guide (SDG) instructions</a>.</p><p>Please refer to <a target=\"_blank\" rel=\"nofollow\" href=\"https://digitalsupport.ge.com/s/article/GE-Digital-CIMPLICITY-Memory-Corruption-Vulnerability\">GE Digital’s security bulletin</a>&nbsp;for more information.</p>\n\n<br>"}],"value":"\nTo obtain the latest versions of GE CIMPLICITY, contact your local GE Digital representative at  https://digitalsupport.ge.com/s/contactsupport https://digitalsupport.ge.com/s/contactsupport .\n\nExploit is only possible if an authenticated user with local access to the system obtains and opens a document from a malicious source so secure deployment and strong access management by users is essential. GE Digital and customers have a shared responsibility for security and users are required to adhere to the most recent  Secure Deployment Guide (SDG) instructions https://digitalsupport.ge.com/s/article/CIMPLICITY-Secure-Deployment-Guide2 .\n\nPlease refer to  GE Digital’s security bulletin https://digitalsupport.ge.com/s/article/GE-Digital-CIMPLICITY-Memory-Corruption-Vulnerability  for more information.\n\n\n\n\n"}],"credits":[{"lang":"en","value":"Michael Heinzl reported this vulnerability to CISA."}],"impact":{"cvss":[{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":6.6,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H","version":"3.1"}]}},"nvd":{"publishedDate":"2023-07-19 14:15:00","lastModifiedDate":"2023-07-28 13:47:00","problem_types":["CWE-787"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ge:cimplicity:*:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}