CVE-2016-9360
Status: ModifiedMedium (6.7)—
An issue was discovered in General Electric (GE) Proficy HMI/SCADA iFIX Version 5.8 SIM 13 and prior versions, Proficy HMI/SCADA CIMPLICITY Version 9.0 and prior versions, and Proficy Historian Version 6.0 and prior versions. An attacker may be able to retrieve user passwords if he or she has access to an authenticated session.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L
- Base score: 6.7
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.37%
- Percentile among all scored CVEs: 28
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (3)
CWEs
- CWE-522
References
Raw JSON (NVD)
Show
{
"id": "CVE-2016-9360",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.4,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.4,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.7,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "LOW",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.3,
"exploitabilityScore": 0.8
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "n/a",
"product": "GE Proficy HMI/SCADA iFIX, Proficy HMI/SCADA CIMPLICITY, and Proficy Historian",
"versions": [
{
"status": "affected",
"version": "GE Proficy HMI/SCADA iFIX, Proficy HMI/SCADA CIMPLICITY, and Proficy Historian"
}
]
}
]
}
],
"published": "2017-02-13T21:59:02.050",
"references": [
{
"url": "http://www.securityfocus.com/bid/95630",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "http://www.securitytracker.com/id/1037809",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-16-336-05A",
"tags": [
"Mitigation",
"Third Party Advisory",
"US Government Resource"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "http://www.securityfocus.com/bid/95630",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1037809",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-16-336-05A",
"tags": [
"Mitigation",
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-522"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in General Electric (GE) Proficy HMI/SCADA iFIX Version 5.8 SIM 13 and prior versions, Proficy HMI/SCADA CIMPLICITY Version 9.0 and prior versions, and Proficy Historian Version 6.0 and prior versions. An attacker may be able to retrieve user passwords if he or she has access to an authenticated session."
},
{
"lang": "es",
"value": "Se encontró un problema en General Electric (GE) Proficy HMI/SCADA iFIX Version 5.8 SIM 13 y versiones anteriores, Proficy HMI/SCADA CIMPLICITY Versión 9.0 y versiones anteriores y Proficy Historian Versión 6.0 y versiones anteriores. Un atacante puede recuperar contraseñas de usuario si tiene acceso a una sesión autenticada."
}
],
"lastModified": "2026-06-17T00:55:52.667",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ge:cimplicity:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B1F646B5-A9D5-4D7A-A39E-B7393B2926B8",
"versionEndIncluding": "9.0"
},
{
"criteria": "cpe:2.3:a:ge:historian:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "58D8576D-3745-47AC-AFB5-AD7BEC33E906",
"versionEndIncluding": "6.0"
},
{
"criteria": "cpe:2.3:a:ge:ifix:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D226196E-5F36-4919-B975-AFDAE6340855",
"versionEndIncluding": "5.8"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}