CVE-2023-0598

HIGH

GE Digital Proficy iFIX 2022 v6.1 v6.5 - Code Injection via Malicious Configuration Files

Title source: llm
STIX 2.1

Description

GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vulnerable to code injection, which may allow an attacker to insert malicious configuration files in the expected web server execution path and gain full control of the HMI software.

References (2)

Core 2

Scores

CVSS v3 7.8
EPSS 0.0057
EPSS Percentile 42.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (3)
ge/ifix 6.1
ge/ifix 6.5
ge/ifix 2022
Published Mar 16, 2023
Tracked Since Feb 18, 2026