CVE-2023-4487

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/09/2023
Last modified:
09/09/2023

Description

<br /> GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected web server execution path to escalate privileges and gain full control of the HMI software.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ge:cimplicity:2023:-:*:*:*:*:*:*