Multiple Generel Electric Product Shell upload Vulnerabilities
Release date:
Updated on:
Affected Systems:
General Electric Proficy HMI/SCADA-CIMPLICITY <8.2 SIM 24
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65117
CVE (CAN) ID: CVE-2014-0751
GE is a multinational company in the United States that provides technical and service services.
Proficy HMI/SCADA-CIMPLICITY 4.01-8.2, Proficy Process Systems with cimplicitycimwebserver.exe (WebView component) has the Arbitrary File Upload Vulnerability, which allows remote attackers to execute arbitrary code.
<* Source: amisto0x07
Z0mb1E
Link: http://ics-cert.us-cert.gov/advisories/ICSA-14-023-01
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
General Electric
----------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Proficy HMI/SCADA-CIMPLICITY 8.2 SIM 24:
Http://support.ge-ip.com/support/index? Page = dwchannel & id = DN4128
GE product security announcement location:
Http://support.ge-ip.com/support/index? Page = kbchannel & id = KB15940