CVE-2014-0750
Directory traversal vulnerability in gefebt.exe in the WebView CimWeb components in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY through 8.2 SIM 24, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 70.2%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Directory traversal vulnerability in gefebt.exe in the WebView CimWeb components in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY through 8.2 SIM 24, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary code via a crafted HTTP request, aka ZDI-CAN-1622.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 70.22% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- ge/intelligent platforms proficy hmi\%2fscada cimplicity · ge/intelligent platforms proficy hmi\/scada cimplicity · ge/intelligent platforms proficy process systems with cimplicity
- Source
- ics-cert@hq.dhs.gov
References
- http://support.ge-ip.com/support/index?page=kbchannel&id=KB15939Vendor Advisory
- http://www.securityfocus.com/bid/65124
- https://www.cisa.gov/news-events/ics-advisories/icsa-14-023-01
- http://ics-cert.us-cert.gov/advisories/ICSA-14-023-01US Government Resource
- http://support.ge-ip.com/support/index?page=kbchannel&id=KB15939Vendor Advisory
- http://www.securityfocus.com/bid/65124
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.