CVE Published: 07/12/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: icscert |
Vendor: GE |
Product: CIMPLICITY Status : PUBLISHED
CVE-2022-2002 Description
GE CIMPICITY versions 2022 and prior is
vulnerable when data from faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, which could allow an attacker to execute arbitrary code.
Metrics
CVSS Version: 3.1 |
Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H