CVE-2022-23921
Severity CVSS v4.0:
Pending analysis
Type:
CWE-269
Improper Privilege Management
Publication date:
25/02/2022
Last modified:
08/03/2022
Description
Exploitation of this vulnerability may result in local privilege escalation and code execution. GE maintains exploitation of this vulnerability is only possible if the attacker has login access to a machine actively running CIMPLICITY, the CIMPLICITY server is not already running a project, and the server is licensed for multiple projects.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
3.70
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ge:proficy_cimplicitiy:*:*:*:*:*:*:*:* | 11.1 (including) |
To consult the complete list of CPE names with products and versions, see this page



