General Electric (GE) Digital Proficy HMI/SCADA - CIMPLICITY before 8.2 SIM 27 mishandles service DACLs, which allows local users to modify a service configuration via unspecified vectors.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-16-194-02 | third party advisory us government resource |
https://ge-ip.force.com/communities/en_US/Article/GE-Digital-Security-Advisory-GED-16-01 | permissions required vendor advisory |
http://www.securityfocus.com/bid/91727 | vdb entry third party advisory broken link |