GE Proficy HMI/SCADA Path Traversal
Vulnerability Description
The CIMPLICITY Web-based access component, CimWebServer, does not check the location of shell files being loaded into the system. By modifying the source location, an attacker could send shell code to the CimWebServer which would deploy the nefarious files as part of any SCADA project. This could allow the attacker to execute arbitrary code.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-0751
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- amisto0x07 and Z0mb1E of Zero Day Initiative (ZDI)