Exploitation of this vulnerability may result in local privilege escalation and code execution. GE maintains exploitation of this vulnerability is only possible if the attacker has login access to a machine actively running CIMPLICITY, the CIMPLICITY server is not already running a project, and the server is licensed for multiple projects.
2022-02-25T19:15:24.890
2024-11-21T06:49:27.780
Modified
CVSSv3.1: 7.5 (HIGH)
AV:L/AC:H/Au:N/C:P/I:P/A:P
1.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ge | proficy_cimplicitiy | ≤ 11.1 | Yes |