GE Proficy Historian Web Administrator XSS
GE Proficy Historian Web Administrator contains a reflected cross-site scripting (XSS) vulnerability in all versions. An attacker can inject malicious JavaScript into the web interface, which executes in the browser of any user who visits a crafted link or form input. This can compromise user sessions and allow unauthorized access to historian configuration and historical process data. The vulnerability affects all versions of Proficy Historian and any Proficy HMI/SCADA systems (CIMPLICITY 8.1/8.2, iFIX 5.0/5.1) with Historian installed.
- Network access to the Proficy Historian Web Administrator interface (port 80 or 443)
- Target user must click a malicious link or visit the application while logged in
- No authentication required from the attacker to inject the payload
Patching may require device reboot — plan for process interruption
/api/v1/advisories/c6c32877-ee9b-4f0d-b495-87b7b22b2956Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.