GE Digital Proficy Code Injection
CVE-2023-0598

7.8HIGH

Key Information:

Vendor

Ge Digital

Vendor
CVE Published:
16 March 2023

What is CVE-2023-0598?

GE Digital Proficy iFIX versions 2022, v6.1, and v6.5 are susceptible to a code injection vulnerability. This flaw could allow an attacker to inject malicious configuration files into the expected web server execution path, potentially granting them complete control over the Human-Machine Interface (HMI) software. As a result, it poses serious risks to operational security and the integrity of industrial control systems. Users should review their deployment configurations and apply necessary precautions to mitigate the impact of this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Proficy iFIX 2022

Proficy iFIX v6.1

Proficy iFIX v6.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Heinzl reported this vulnerability to CISA.
.