CVE-2016-9360

An issue was discovered in General Electric (GE) Proficy HMI/SCADA iFIX Version 5.8 SIM 13 and prior versions, Proficy HMI/SCADA CIMPLICITY Version 9.0 and prior versions, and Proficy Historian Version 6.0 and prior versions. An attacker may be able to retrieve user passwords if he or she has access to an authenticated session.
References
Link Resource
https://ics-cert.us-cert.gov/advisories/ICSA-16-336-05A Mitigation Third Party Advisory US Government Resource
http://www.securityfocus.com/bid/95630 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1037809 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ge:cimplicity:*:*:*:*:*:*:*:*
cpe:2.3:a:ge:historian:*:*:*:*:*:*:*:*
cpe:2.3:a:ge:ifix:*:*:*:*:*:*:*:*

Information

Published : 2017-02-13 13:59

Updated : 2022-02-03 11:40


NVD link : CVE-2016-9360

Mitre link : CVE-2016-9360


JSON object : View

CWE
CWE-522

Insufficiently Protected Credentials

Advertisement

dedicated server usa

Products Affected

ge

  • ifix
  • historian
  • cimplicity