CVE-2022-46660

An unauthorized user could alter or write files with full control over the path and content of the file.
References
Link Resource
https://digitalsupport.ge.com/s/article/GE-Digital-Product-Security-Advisory-GED-23-01 Permissions Required Vendor Advisory
https://www.cisa.gov/uscert/ics/advisories/icsa-23-017-01 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:a:ge:proficy_historian:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:55

Type Values Removed Values Added
Summary An unauthorized user could alter or write files with full control over the path and content of the file. An unauthorized user could alter or write files with full control over the path and content of the file.

25 Jan 2023, 16:52

Type Values Removed Values Added
CPE cpe:2.3:a:ge:proficy_historian:*:*:*:*:*:*:*:*
First Time Ge
Ge proficy Historian
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References (MISC) https://digitalsupport.ge.com/s/article/GE-Digital-Product-Security-Advisory-GED-23-01 - (MISC) https://digitalsupport.ge.com/s/article/GE-Digital-Product-Security-Advisory-GED-23-01 - Permissions Required, Vendor Advisory
References (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-23-017-01 - (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-23-017-01 - Third Party Advisory, US Government Resource

18 Jan 2023, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-18 00:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-46660

Mitre link : CVE-2022-46660

CVE.ORG link : CVE-2022-46660


JSON object : View

Products Affected

ge

  • proficy_historian
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type