Directory traversal vulnerability in substitute.bcl in the WebView CimWeb subsystem in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to read arbitrary files via a crafted packet.
2013-01-27T18:55:03.460
2025-04-11T00:51:21.963
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:N/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ge | intelligent_platforms_proficy_hmi\/scada_cimplicity | 4.01 | Yes |
Application | ge | intelligent_platforms_proficy_hmi\/scada_cimplicity | 7.5 | Yes |
Application | ge | intelligent_platforms_proficy_hmi\/scada_cimplicity | 8.0 | Yes |
Application | ge | intelligent_platforms_proficy_process_systems_with_cimplicity | - | Yes |
Hardware | ge | intelligent_platforms_proficy_process_systems | - | Yes |