CVE Published: 25/02/2022 |
CVE Updated: 17/09/2024 |
CVE Year: 2022 Source: icscert |
Vendor: General Electric |
Product: Proficy CIMPLICITY Status : PUBLISHED
CVE-2022-23921 Description
Exploitation of this vulnerability may result in local privilege escalation and code execution. GE maintains exploitation of this vulnerability is only possible if the attacker has login access to a machine actively running CIMPLICITY, the CIMPLICITY server is not already running a project, and the server is licensed for multiple projects.
Metrics
CVSS Version: 3.1 |
Base Score: 7.5 HIGH Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H