GE Proficy CIMPLICITY Directory Traversal and Remote Command Execution Vulnerabilities
BID:57505
Info
GE Proficy CIMPLICITY Directory Traversal and Remote Command Execution Vulnerabilities
| Bugtraq ID: | 57505 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-0653 CVE-2013-0654 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 22 2013 12:00AM |
| Updated: | Jan 22 2013 12:00AM |
| Credit: | Vendor reported these issues. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
GE Proficy CIMPLICITY Directory Traversal and Remote Command Execution Vulnerabilities
The CIMPLICITY component is prone to a directory-traversal vulnerability and a remote command-execution vulnerability because it fails to properly validate user-supplied data.
An attacker can exploit these issues to view or download arbitrary files from the server and execute arbitrary commands within the context of the server running the affected application. Failed exploit attempts will result in a denial-of-service condition.
The CIMPLICITY component is prone to a directory-traversal vulnerability and a remote command-execution vulnerability because it fails to properly validate user-supplied data.
An attacker can exploit these issues to view or download arbitrary files from the server and execute arbitrary commands within the context of the server running the affected application. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
GE Proficy CIMPLICITY Directory Traversal and Remote Command Execution Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
GE Proficy CIMPLICITY Directory Traversal and Remote Command Execution Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
GE Proficy CIMPLICITY Directory Traversal and Remote Command Execution Vulnerabilities
References:
References:
- Proficy HMI/SCADA - CIMPLICITY Homepage (General Electric)
- ICSA-13-022-02�??GE INTELLIGENT PLATFORMS PROFICY CIMPLICITY MULTIPLE VULNERABILIT (ICS-CERT)