ICSA-20-098-02
·
Published 2020-04-07
·
View on CISA ICS-CERT ↗
GE Digital CIMPLICITY
CVSS 6.0
MEDIUM
Risk Summary
Successful exploitation of this vulnerability could allow an adversary to modify the systemwide CIMPLICITY configuration, leading to the arbitrary execution of code.
CVEs (1)
Remediations
- GE Digital CIMPLICITY v11.0, released January 2020, contains mitigation for this local privilege escalation vulnerability. GE Digital recommends all users upgrade to GE CIMPLICITY v11.0 or newer. Other recommendations may mitigate issues, but only installing the most current version will fully address the issue. To obtain the latest version of this product, please contact a GE Digital representative.
- GE Digital provides guidance for users to secure systems, and advises that users running CIMPLICITY adhere to the Secure Deployment Guide found on GE Digital's customer center (requires logon).
Affected Vendors
General Electric (GE)
Affected Products (1)
General Electric (GE)
·
GE Digital CIMPLICITY
<= 10.0
Affected Sectors
Chemical, Critical Manufacturing, Energy, Food and Agriculture, Water
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more