CVE-2013-2785
Last modified
CVE-2013-2785 is a vulnerability of currently unknown severity. Multiple buffer overflows in CimWebServer.exe in the WebView component in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY before 8.0 SIM 27, 8.1 before SIM 25, and 8.2 before SIM 19, and Proficy Process Systems with CIMPLICITY, allow remote attackers to execute arbitrary code via crafted data in packets to TCP port 10212, aka ZDI-CAN-1621 and ZDI-CAN-1624.. EPSS estimates a 3.77% chance of exploitation in the next 30 days.
Description
Multiple buffer overflows in CimWebServer.exe in the WebView component in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY before 8.0 SIM 27, 8.1 before SIM 25, and 8.2 before SIM 19, and Proficy Process Systems with CIMPLICITY, allow remote attackers to execute arbitrary code via crafted data in packets to TCP port 10212, aka ZDI-CAN-1621 and ZDI-CAN-1624.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ge | Intelligent Platforms Proficy Hmi\/Scada Cimplicity | 8.0 |
| Ge | Intelligent Platforms Proficy Hmi\/Scada Cimplicity | 8.1 |
| Ge | Intelligent Platforms Proficy Hmi\/Scada Cimplicity | 8.2 |
| Ge | Intelligent Platforms Proficy Process Systems With Cimplicity | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-2785?
How severe is CVE-2013-2785?
How do I fix CVE-2013-2785?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-2779Cisco IOS XE 3.4 before 3.4.5S, and 3.5 through 3.7 before 3…
- CVE-2013-2780Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attack…
- CVE-2013-2781Use-after-free vulnerability in the server application in 3S…
- CVE-2013-2782Schneider Electric Trio J-Series License Free Ethernet Radio…
- CVE-2013-2783The DNP3 driver in IOServer drivers 1.0.19.0 allows remote a…
- CVE-2013-2784Triangle Research International (aka Tri) Nano-10 PLC device…
- CVE-2013-2786Alstom Grid MiCOM S1 Agile before 1.0.3 and Alstom Grid MiCO…
- CVE-2013-2787Alstom e-terracontrol 3.5, 3.6, and 3.7 allows remote attack…
- CVE-2013-2788The DNP3 Slave service in SUBNET Solutions SubSTATION Server…
- CVE-2013-2789The Kepware DNP Master Driver for the KEPServerEX Communicat…
- CVE-2013-2790The master-station DNP3 driver before driver19.exe, and Beta…
- CVE-2013-2791MatrikonOPC SCADA DNP3 OPC Server 1.2.0 allows remote attack…
Are you affected by CVE-2013-2785?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
