QID 591234

Date Published: 2022-12-15

QID 591234: GE Proficy CIMPLICITY Sensitive Information Disclosure Vulnerability (ICSA-22-053-02)

A vulnerability was discovered in GE Proficy CIMPLICITY, which relates to cleartext transmission of sensitive information.

AFFECTED PRODUCTS The following versions of Proficy CIMPLICITY, an HMI and SCADA platform, are affected:
Proficy CIMPLICITY: All versions

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys

Successful exploitation of this vulnerability could allow an attacker to capture a connection session, resulting in disclosure of sensitive information.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-22-053-02 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591234

    Software Advisories
    Advisory ID Software Component Link