← Back

Intelligent Platforms Proficy Hmi/scada Cimplicity

intelligent_platforms_proficy_hmi/scada_cimplicity

Vendor: Ge • 10 CVEs

CVEs (10)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ge
1Intelligent Platforms Proficy Hmi/scada Cimplicity
May 13, 2026
Oct 5, 2017
N/A· v4
6.8 MEDIUM· v3
4.9 MEDIUM· v2
A Stack-based Buffer Overflow issue was discovered in GE CIMPLICITY Versions 9.0 and prior. A function reads a packet to indicate the next packet length. The next packet length is not verified, allowing a buffer overwrit...Show more
A Stack-based Buffer Overflow issue was discovered in GE CIMPLICITY Versions 9.0 and prior. A function reads a packet to indicate the next packet length. The next packet length is not verified, allowing a buffer overwrite that could lead to an arbitrary remote code execution.Show less
1Ge
1Intelligent Platforms Proficy Hmi/scada Cimplicity
May 6, 2026
Jan 17, 2015
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The (1) CimView and (2) CimEdit components in GE Proficy HMI/SCADA-CIMPLICITY 8.2 and earlier allow remote attackers to gain privileges via a crafted CIMPLICITY screen (aka .CIM) file.
1Ge
3Intelligent Platforms Proficy Hmi%2fscada Cimplicity
Intelligent Platforms Proficy Hmi/scada CimplicityIntelligent Platforms Proficy Process Systems With Cimplicity
Apr 29, 2026
Jan 25, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The CIMPLICITY Web-based access component, CimWebServer, does not check the location of shell files being loaded into the system. By modifying the source location, an attacker could send shell code to the CimWebServer...Show more
The CIMPLICITY Web-based access component, CimWebServer, does not check the location of shell files being loaded into the system. By modifying the source location, an attacker could send shell code to the CimWebServer which would deploy the nefarious files as part of any SCADA project. This could allow the attacker to execute arbitrary code.Show less
1Ge
3Intelligent Platforms Proficy Hmi%2fscada Cimplicity
Intelligent Platforms Proficy Hmi/scada CimplicityIntelligent Platforms Proficy Process Systems With Cimplicity
Apr 29, 2026
Jan 25, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in gefebt.exe in the WebView CimWeb components in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY through 8.2 SIM 24, and Proficy Process Systems with CIMPLICITY, allows remote a...Show more
Directory traversal vulnerability in gefebt.exe in the WebView CimWeb components in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY through 8.2 SIM 24, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary code via a crafted HTTP request, aka ZDI-CAN-1622.Show less
2Catapultsoftware
Ge
4Catapult Dnp3 I/o Driver
Intelligent Platforms Proficy Dnp3 I/o DriverIntelligent Platforms Proficy Hmi/scada Cimplicity+1 more
Apr 29, 2026
Nov 22, 2013
N/A· v4
N/A· v3
4.7 MEDIUM· v2
The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (aka the DNP master station server) in GE Intelligent Platforms Proficy HM...Show more
The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (aka the DNP master station server) in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY and iFIX, allow physically proximate attackers to cause a denial of service (infinite loop) via crafted input over a serial line.Show less
2Catapultsoftware
Ge
4Catapult Dnp3 I/o Driver
Intelligent Platforms Proficy Dnp3 I/o DriverIntelligent Platforms Proficy Hmi/scada Cimplicity+1 more
Apr 29, 2026
Nov 22, 2013
N/A· v4
N/A· v3
7.1 HIGH· v2
The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (aka the DNP master station server) in GE Intelligent Platforms Proficy HM...Show more
The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (aka the DNP master station server) in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY and iFIX, allow remote attackers to cause a denial of service (infinite loop) via a crafted DNP3 TCP packet.Show less
1Ge
2Intelligent Platforms Proficy Hmi/scada Cimplicity
Intelligent Platforms Proficy Process Systems With Cimplicity
Apr 29, 2026
Jul 31, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple buffer overflows in CimWebServer.exe in the WebView component in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY before 8.0 SIM 27, 8.1 before SIM 25, and 8.2 before SIM 19, and Proficy Process Systems w...Show more
Multiple buffer overflows in CimWebServer.exe in the WebView component in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY before 8.0 SIM 27, 8.1 before SIM 25, and 8.2 before SIM 19, and Proficy Process Systems with CIMPLICITY, allow remote attackers to execute arbitrary code via crafted data in packets to TCP port 10212, aka ZDI-CAN-1621 and ZDI-CAN-1624.Show less
1Ge
3Intelligent Platforms Proficy Hmi/scada Cimplicity
Intelligent Platforms Proficy Process SystemsIntelligent Platforms Proficy Process Systems With Cimplicity
Apr 29, 2026
Jan 27, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
CimWebServer in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary commands or cause a denial of service (d...Show more
CimWebServer in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary commands or cause a denial of service (daemon crash) via a crafted packet.Show less
1Ge
3Intelligent Platforms Proficy Hmi/scada Cimplicity
Intelligent Platforms Proficy Process SystemsIntelligent Platforms Proficy Process Systems With Cimplicity
Apr 29, 2026
Jan 27, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in substitute.bcl in the WebView CimWeb subsystem in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote...Show more
Directory traversal vulnerability in substitute.bcl in the WebView CimWeb subsystem in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to read arbitrary files via a crafted packet.Show less
1Ge
3Intelligent Platforms Proficy Hmi/scada Cimplicity
Intelligent Platforms Proficy Process SystemsIntelligent Platforms Proficy Process Systems With Cimplicity
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Integer overflow in CimWebServer.exe in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to cause a denial of service (daemon...Show more
Integer overflow in CimWebServer.exe in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to cause a denial of service (daemon crash) via a malformed HTTP request.Show less