[Control systems] GE Digital security advisory (AV23-150)

Serial number: AV23-150
Date: March 15, 2023

On March 14, 2023, CISA published an ICS Advisory to address a vulnerability VulnerabilityA flaw or weakness in the design or implementation of an information system or its environment that could be exploited to adversely affect an organization's assets or operations. in the following product:

  • GE Digital Proficy iFIX – versions 2022, 6.1 and 6.5

Exploitation of this vulnerability could lead to a full system compromise CompromiseThe intentional or unintentional disclosure of information, which adversely impacts its confidentiality, integrity, or availability. .

The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.

Date modified: