An unauthorized user could be able to read any file on the system, potentially exposing sensitive information.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NGe Proficy Historian
APPGe7.0 – 2023 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Related vulnerabilities
CVE-2022-46732CRITICAL9.8PL ✓same product
GE Proficy Historian — pominięcie uwierzytelnienia lokalnej usługi (CWE-306)
CVE-2022-38469HIGH7.5same product
An unauthorized user with network access and the decryption key could decrypt sensitive data, such as user...
CVE-2022-46331HIGH7.5same product
An unauthorized user could possibly delete any file on the system.
CVE-2022-46660HIGH7.5same product
An unauthorized user could alter or write files with full control over the path and content of the file. ...
CVE-2023-5908CRITICAL9.1PL ✓same vendor
Buffer overflow w KEPServerEX umożliwiający crash lub wyciek danych