CVE-2023-4487: Ge Cimplicity

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected web server execution path to escalate privileges and gain full control of the HMI software.

Affected products

  • Ge Cimplicity: version 2023 only

Published 2023-09-05. Last modified 2026-06-17.