CVE-2014-0751
Published Jan 25, 2014
Last updated 11 years ago
Overview
- Description
- Directory traversal vulnerability in CimWebServer.exe (aka the WebView component) in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY before 8.2 SIM 24, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary code via a crafted message to TCP port 10212, aka ZDI-CAN-1623.
- Source
- ics-cert@hq.dhs.gov
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-22
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ge:intelligent_platforms_proficy_hmi\\%2fscada_cimplicity:*:sim24:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4C5EDB9D-01CD-4843-86CD-C834B726ACF1", "versionEndIncluding": "8.2" }, { "criteria": "cpe:2.3:a:ge:intelligent_platforms_proficy_hmi\\/scada_cimplicity:4.01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6C0B8CA7-2161-4603-B844-DE6C079DF36F" }, { "criteria": "cpe:2.3:a:ge:intelligent_platforms_proficy_hmi\\/scada_cimplicity:7.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E3BACB11-5CD3-4CA6-9C56-D71628CADF0F" }, { "criteria": "cpe:2.3:a:ge:intelligent_platforms_proficy_hmi\\/scada_cimplicity:8.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "90538C50-38BD-4EE5-BD30-96E2E2951FE3" }, { "criteria": "cpe:2.3:a:ge:intelligent_platforms_proficy_hmi\\/scada_cimplicity:8.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CB261867-B9B1-4D3D-B2DE-3CC3164EFD06" }, { "criteria": "cpe:2.3:a:ge:intelligent_platforms_proficy_hmi\\/scada_cimplicity:8.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "559DCD7A-0745-4D4C-A77A-83240EF6C510" }, { "criteria": "cpe:2.3:a:ge:intelligent_platforms_proficy_process_systems_with_cimplicity:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AD9711EA-2C95-41FA-8827-01FCB0ED4B06" } ], "operator": "OR" } ] } ]