ID

VAR-201612-0529


TITLE

Remote Denial of Service Vulnerability in GE Configuration Software iFIX V5.8

Trust: 0.6

sources: CNVD: CNVD-2016-11928

DESCRIPTION

GE Proficy HMI / SCADA-iFIX configuration software is used for process visualization, data acquisition, analysis, and operation monitoring. The software uses the SCADA engine, has multiple connection options, and uses an open, highly scalable distributed network model. A remote denial of service vulnerability exists in the GE configuration software iFIX V5.8. Because the IFix configuration system fails to properly receive the input data of the Modbus PLC, a remote attacker can use this vulnerability to trigger the configuration system to stop working from a lower computer and launch a remote denial of service attack

Trust: 0.72

sources: CNVD: CNVD-2016-11928 // IVD: 877a5540-d450-4d0f-b3ea-cfab47a200ce

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 877a5540-d450-4d0f-b3ea-cfab47a200ce // CNVD: CNVD-2016-11928

AFFECTED PRODUCTS

vendor:ge intellutionmodel:ifix configuration systemscope:eqversion:5.8

Trust: 0.6

vendor:ge intellution themodel:ifix configuration systemscope:eqversion:5.8

Trust: 0.2

sources: IVD: 877a5540-d450-4d0f-b3ea-cfab47a200ce // CNVD: CNVD-2016-11928

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2016-11928
value: MEDIUM

Trust: 0.6

IVD: 877a5540-d450-4d0f-b3ea-cfab47a200ce
value: MEDIUM

Trust: 0.2

CNVD: CNVD-2016-11928
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 877a5540-d450-4d0f-b3ea-cfab47a200ce
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: 877a5540-d450-4d0f-b3ea-cfab47a200ce // CNVD: CNVD-2016-11928

TYPE

Denial of service

Trust: 0.2

sources: IVD: 877a5540-d450-4d0f-b3ea-cfab47a200ce

PATCH

title:Remote Denial of Service Vulnerability in GE Configuration Software iFIX 5.8url:https://www.cnvd.org.cn/patchinfo/show/84916

Trust: 0.6

sources: CNVD: CNVD-2016-11928

EXTERNAL IDS

db:CNVDid:CNVD-2016-11928

Trust: 0.8

db:IVDid:877A5540-D450-4D0F-B3EA-CFAB47A200CE

Trust: 0.2

sources: IVD: 877a5540-d450-4d0f-b3ea-cfab47a200ce // CNVD: CNVD-2016-11928

SOURCES

db:IVDid:877a5540-d450-4d0f-b3ea-cfab47a200ce
db:CNVDid:CNVD-2016-11928

LAST UPDATE DATE

2022-05-17T01:36:34.269000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-11928date:2016-12-12T00:00:00

SOURCES RELEASE DATE

db:IVDid:877a5540-d450-4d0f-b3ea-cfab47a200cedate:2016-12-07T00:00:00
db:CNVDid:CNVD-2016-11928date:2017-01-13T00:00:00