Lucene search

K
cve[email protected]CVE-2013-0653
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2013-0653

2022-10-0316:15:02
CWE-22
web.nvd.nist.gov
100
cve-2013-0653
directory traversal
webview cimweb
ge intelligent platforms
proficy hmi/scada
cimplicity
proficy process systems
vulnerability
remote attackers
arbitrary files

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

6.7 Medium

AI Score

Confidence

Low

0.015 Low

EPSS

Percentile

86.8%

Directory traversal vulnerability in substitute.bcl in the WebView CimWeb subsystem in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to read arbitrary files via a crafted packet.

Affected configurations

NVD
Node
geintelligent_platforms_proficy_hmi\/scada_cimplicityMatch4.01
OR
geintelligent_platforms_proficy_hmi\/scada_cimplicityMatch7.5
OR
geintelligent_platforms_proficy_hmi\/scada_cimplicityMatch8.0
Node
geintelligent_platforms_proficy_process_systems_with_cimplicityMatch-
AND
geintelligent_platforms_proficy_process_systemsMatch-

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

6.7 Medium

AI Score

Confidence

Low

0.015 Low

EPSS

Percentile

86.8%