4.6
CVSSv2

CVE-2020-6992

Published: 15/04/2020 Updated: 22/04/2020
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.7 | Impact Score: 5.9 | Exploitability Score: 0.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A local privilege escalation vulnerability has been identified in the GE Digital CIMPLICITY HMI/SCADA product v10.0 and prior. If exploited, this vulnerability could allow an adversary to modify the system, leading to the arbitrary execution of code. This vulnerability is only exploitable if an attacker has access to an authenticated session. GE Digital CIMPLICITY v11.0, released January 2020, contains mitigation for this local privilege escalation vulnerability. GE Digital recommends all users upgrade to GE CIMPLICITY v11.0 or newer.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ge cimplicity

Github Repositories

improve mulval to accommodate some updates and make it more suitable for industrial control network

Sicsp_ICS In this project, we first proposed semi-passive information acquisition to obtain necessary network information considering the particularity of ICS network Further, thanks to the relatively comprehensive network information obtained, attack graphs can be generated for network situational awareness Finally, network administrators can use the network topology map, a