CVE-2022-23921

HIGH

GE Proficy CIMPLICITY < 11.1 - Authenticated Local Privilege Escalation and Code Execution

Title source: llm
STIX 2.1

Description

Exploitation of this vulnerability may result in local privilege escalation and code execution. GE maintains exploitation of this vulnerability is only possible if the attacker has login access to a machine actively running CIMPLICITY, the CIMPLICITY server is not already running a project, and the server is licensed for multiple projects.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://www.cisa.gov/uscert/ics/advisories/icsa-22-053-01

Scores

CVSS v3 7.5
EPSS 0.0020
EPSS Percentile 9.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
ge/proficy_cimplicitiy < 11.1
Published Feb 25, 2022
Tracked Since Feb 18, 2026