Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-0598


GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vulnerable to code injection, which may allow an attacker to insert malicious configuration files in the expected web server execution path and gain full control of the HMI software.


Published

2023-03-16T20:15:11.327

Last Modified

2024-11-21T07:37:27.820

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ge ifix 6.1 Yes
Application ge ifix 6.5 Yes
Application ge ifix 2022 Yes

References