Vulnerabilities > CVE-2016-5787 - Exposure of Resource to Wrong Sphere vulnerability in GE Cimplicity

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
ge
CWE-668

Summary

General Electric (GE) Digital Proficy HMI/SCADA - CIMPLICITY before 8.2 SIM 27 mishandles service DACLs, which allows local users to modify a service configuration via unspecified vectors.

Vulnerable Configurations

Part Description Count
Application
Ge
31

Common Weakness Enumeration (CWE)