Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-3463

Опубликовано: 19 июл. 2023
Источник: nvd
CVSS3: 6.6
CVSS3: 9.8
EPSS Низкий

Описание

All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sources are vulnerable to memory corruption issues due to insufficient input validation, including issues such as out-of-bounds reads and writes, use-after-free, stack-based buffer overflows, uninitialized pointers, and a heap-based buffer overflow. Successful exploitation could allow an attacker to execute arbitrary code.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ge:cimplicity:*:*:*:*:*:*:*:*

EPSS

Процентиль: 32%
0.00124
Низкий

6.6 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-122
CWE-787

Связанные уязвимости

CVSS3: 6.6
github
больше 2 лет назад

All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sources are vulnerable to memory corruption issues due to insufficient input validation, including issues such as out-of-bounds reads and writes, use-after-free, stack-based buffer overflows, uninitialized pointers, and a heap-based buffer overflow. Successful exploitation could allow an attacker to execute arbitrary code.

CVSS3: 9.8
fstec
больше 2 лет назад

Уязвимость клиент-серверного приложения обработки данных и контроля технологических операций Proficy HMI/SCADA CIMPLICITY, связанная с возможностью записи за пределами буфера в памяти, позволяющая нарушителю произвольный код путем загрузки вредоносного файла

EPSS

Процентиль: 32%
0.00124
Низкий

6.6 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-122
CWE-787