PatchSiren

Ge CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Ge CVE published 2017-02-13

CVE-2016-9360

CVE-2016-9360 is a credential exposure issue in several GE Proficy HMI/SCADA products. According to the CVE record, an attacker who already has access to an authenticated session may be able to retrieve user passwords. The affected product ranges listed in NVD are iFIX 5.8 SIM 13 and prior, CIMPLICITY 9.0 and prior, and Historian 6.0 and prior. NVD classifies the issue as CVSS 6.7 (Medium) with CWE-522, a [truncated]