CVE-2022-46732

CRITICAL

GE Proficy Historian 7.0-2023 - Unauthenticated Command Execution

Title source: llm
STIX 2.1

Description

Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication status.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-23-017-01

Scores

CVSS v3 9.8
EPSS 0.0082
EPSS Percentile 52.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (1)
ge/proficy_historian 7.0 - 2023
Published Jan 18, 2023
Tracked Since Feb 18, 2026