Description
The attached security advisory addresses a vulnerability in Proficy Historian, Proficy HMI/SCADA – iFIX, Proficy Pulse, Proficy Batch Execution, and the SI7 I/O Driver.
The attached removal tool unregisters and deletes the vulnerable ActiveX control. The SIMs below ensure that Proficy Historian software functions properly once the control is removed - the SIMs do not remove the vulnerability.
SIMs for Proficy HMI/SCADA – iFIX referenced in GEIP12-04
Run attached removal tool as per the instructions in the security advisory - no SIMs are required.
SIMs for Proficy Pulse referenced in GEIP12-04
Run attached removal tool as per the instructions in the security advisory - no SIMs are required.
SIMs for Proficy Batch Execution referenced in GEIP12-04
Run attached removal tool as per the instructions in the security advisory - no SIMs are required.
SIMs for the SI7 I/O Driver referenced in GEIP12-04
Run attached removal tool as per the instructions in the security advisory - no SIMs are required.
SIMs for Proficy Historian referenced in GEIP12-04
First apply the SIMs below, then run the attached removal tool as per the instructions in the security advisory.
Proficy Historian 4.5 SIM 14 (Note this issue was addressed in SIM 12 / SIM 14 is cumulative)
http://support.ge-ip.com/support/index?page=dwchannel&id=DN3947
Proficy Historian 4.0 SIM 24 at
http://support.ge-ip.com/support/index?page=dwchannel&id=DN3920
Proficy Historian 3.5 SIM 20 at
http://support.ge-ip.com/support/index?page=dwchannel&id=DN3916
Proficy Historian 3.1 SIM IH31_11465436841.exe at
http://support.ge-ip.com/support/index?page=dwchannel&id=DN3824
| Product | Version | Module | | SI7 |
All |
All |
| Batch Execution |
All |
All |
| Pulse |
All |
All |
| Historian |
All |
All |
| HMI/SCADA - iFIX |
All |
All |
|