6.3

CVE-2016-5787

General Electric (GE) Digital Proficy HMI/SCADA - CIMPLICITY before 8.2 SIM 27 mishandles service DACLs, which allows local users to modify a service configuration via unspecified vectors.

Data is provided by the National Vulnerability Database (NVD)
GeCimplicity Version < 8.2
GeCimplicity Version8.2 Updatesim1
GeCimplicity Version8.2 Updatesim10
GeCimplicity Version8.2 Updatesim11
GeCimplicity Version8.2 Updatesim12
GeCimplicity Version8.2 Updatesim13
GeCimplicity Version8.2 Updatesim14
GeCimplicity Version8.2 Updatesim15
GeCimplicity Version8.2 Updatesim16
GeCimplicity Version8.2 Updatesim17
GeCimplicity Version8.2 Updatesim18
GeCimplicity Version8.2 Updatesim19
GeCimplicity Version8.2 Updatesim2
GeCimplicity Version8.2 Updatesim20
GeCimplicity Version8.2 Updatesim21
GeCimplicity Version8.2 Updatesim22
GeCimplicity Version8.2 Updatesim23
GeCimplicity Version8.2 Updatesim24
GeCimplicity Version8.2 Updatesim25
GeCimplicity Version8.2 Updatesim26
GeCimplicity Version8.2 Updatesim3
GeCimplicity Version8.2 Updatesim4
GeCimplicity Version8.2 Updatesim5
GeCimplicity Version8.2 Updatesim6
GeCimplicity Version8.2 Updatesim7
GeCimplicity Version8.2 Updatesim8
GeCimplicity Version8.2 Updatesim9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.09% 0.236
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.3 2 3.7
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-668 Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.