CVE-2023-0898

MEDIUM

GE MiCOM S1 Agile - Uncontrolled Search Path Element

Title source: llm
STIX 2.1

Description

General Electric MiCOM S1 Agile is vulnerable to an attacker achieving code execution by placing malicious DLL files in the directory of the application.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource government-resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-311-23

Scores

CVSS v3 5.3
EPSS 0.0026
EPSS Percentile 16.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-427
Status published
Products (1)
ge/micom_s1_agile
Published Nov 07, 2023
Tracked Since Feb 18, 2026