CVE-2022-2952: Ge Cimplicity

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

GE CIMPICITY versions 2022 and prior is vulnerable when data from a faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, which could allow an attacker to execute arbitrary code.

Affected products

  • Ge Cimplicity: up to and including 2022

Published 2022-12-07. Last modified 2026-06-17.