CVE-2013-0653
Directory traversal vulnerability in substitute.bcl in the WebView CimWeb subsystem in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to read arbitrary files…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 19.1%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Directory traversal vulnerability in substitute.bcl in the WebView CimWeb subsystem in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to read arbitrary files via a crafted packet.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 19.11% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- ge/intelligent platforms proficy hmi\/scada cimplicity · ge/intelligent platforms proficy process systems with cimplicity · ge/intelligent platforms proficy process systems
- Source
- ics-cert@hq.dhs.gov
References
- http://www.us-cert.gov/control_systems/pdf/ICSA-13-022-02.pdfUS Government Resource
- http://www.us-cert.gov/control_systems/pdf/ICSA-13-022-02.pdfUS Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.