CVE-2022-23921 HIGH

CVE-2022-23921: ICSA-22-053-01 GE Proficy CIMPLICITY-IPM

Vendor General Electric
Product Proficy CIMPLICITY
Weakness CWE-269
Published February 25, 2022
Last update April 16, 2025

CVSS base score

7.5/10
Attack vector Adjacent
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Exploitation of this vulnerability may result in local privilege escalation and code execution. GE maintains exploitation of this vulnerability is only possible if the attacker has login access to a machine actively running CIMPLICITY, the CIMPLICITY server is not already running a project, and the server is licensed for multiple projects.

Key dates

02Disclosure timeline

February 25, 2022 CVE published
April 16, 2025 Record updated