CVE-2023-4487: Ge Cimplicity
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected web server execution path to escalate privileges and gain full control of the HMI software.
Affected products
- Ge Cimplicity: version 2023 only
Published 2023-09-05. Last modified 2026-06-17.