Directory traversal vulnerability in CimWebServer.exe (aka the WebView component) in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY before 8.2 SIM 24, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary code via a crafted message to TCP port 10212, aka ZDI-CAN-1623.
2014-01-25T22:55:04.583
2025-04-11T00:51:21.963
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ge | intelligent_platforms_proficy_hmi\%2fscada_cimplicity | ≤ 8.2 | Yes |
Application | ge | intelligent_platforms_proficy_hmi\/scada_cimplicity | 4.01 | Yes |
Application | ge | intelligent_platforms_proficy_hmi\/scada_cimplicity | 7.5 | Yes |
Application | ge | intelligent_platforms_proficy_hmi\/scada_cimplicity | 8.0 | Yes |
Application | ge | intelligent_platforms_proficy_hmi\/scada_cimplicity | 8.1 | Yes |
Application | ge | intelligent_platforms_proficy_hmi\/scada_cimplicity | 8.2 | Yes |
Application | ge | intelligent_platforms_proficy_process_systems_with_cimplicity | - | Yes |