CVE-2022-2948

GE CIMPICITY versions 2022 and prior is vulnerable to a heap-based buffer overflow, which could allow an attacker to execute arbitrary code.

Credits

Kimiya working with Trend micro Zero Day Initiative reported these vulnerabilities to CISA.

References