<?xml version="1.0" encoding="utf-8"?>
<oval-def:oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:ind-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" xmlns:win-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#windows windows-definitions-schema.xsd">
  <oval-def:generator>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2017-01-31T12:34:45</oval:timestamp>
  </oval-def:generator>
  <oval-def:definitions>
    <oval-def:definition id="oval:com.kaspersky.ics-cert:def:1" version="1" class="vulnerability">
      <oval-def:metadata>
        <oval-def:title>GE Proficy HMI SCADA CIMPLICITY Privilege Management Vulnerability - CVE-2016-5787 (GED 16-01)</oval-def:title>
        <oval-def:reference source="CVE" ref_id="CVE-2016-5787" ref_url="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5787" />
        <oval-def:description>
          General Electric (GE) Digital Proficy HMI/SCADA - CIMPLICITY before 8.2 SIM 27 mishandles service DACLs, which allows local users to modify a service configuration via unspecified vectors.
        </oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criteria operator="OR">
          <oval-def:criterion test_ref="oval:com.kaspersky.ics-cert:tst:1" comment="CIMPLICITY version less than 8.1 installed" />
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:com.kaspersky.ics-cert:tst:2" comment="CIMPLICITY version 8.1 installed" />
            <oval-def:criterion test_ref="oval:com.kaspersky.ics-cert:tst:3" comment="CIMPLICITY 8.1 SIM version less than SIM 29 installed" />
          </oval-def:criteria>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:com.kaspersky.ics-cert:tst:4" comment="CIMPLICITY version 8.2 installed" />
            <oval-def:criterion test_ref="oval:com.kaspersky.ics-cert:tst:5" comment="CIMPLICITY 8.2 SIM version less than SIM 27 installed" />
          </oval-def:criteria>
        </oval-def:criteria>
        <oval-def:criterion test_ref="oval:com.kaspersky.ics-cert:tst:6" comment="CIMPLICITY Windows services without DACLs" />
      </oval-def:criteria>
    </oval-def:definition>
  </oval-def:definitions>
  <oval-def:tests>
    <win-def:registry_test id="oval:com.kaspersky.ics-cert:tst:1" check="all" version="1" comment="CIMPLICITY version less than 8.1 installed">
      <win-def:object object_ref="oval:com.kaspersky.ics-cert:obj:7" />
      <win-def:state state_ref="oval:com.kaspersky.ics-cert:ste:1" />
    </win-def:registry_test>
    <win-def:registry_test id="oval:com.kaspersky.ics-cert:tst:2" check="all" version="1" comment="CIMPLICITY version 8.1 installed">
      <win-def:object object_ref="oval:com.kaspersky.ics-cert:obj:7" />
      <win-def:state state_ref="oval:com.kaspersky.ics-cert:ste:4" />
    </win-def:registry_test>
    <win-def:registry_test id="oval:com.kaspersky.ics-cert:tst:3" check="all" check_existence="any_exist" version="1" comment="CIMPLICITY 8.1 SIM version less than SIM 29 installed">
      <win-def:object object_ref="oval:com.kaspersky.ics-cert:obj:9" />
      <win-def:state state_ref="oval:com.kaspersky.ics-cert:ste:2" />
    </win-def:registry_test>
    <win-def:registry_test id="oval:com.kaspersky.ics-cert:tst:4" check="all" version="1" comment="CIMPLICITY version 8.2 installed">
      <win-def:object object_ref="oval:com.kaspersky.ics-cert:obj:7" />
      <win-def:state state_ref="oval:com.kaspersky.ics-cert:ste:5" />
    </win-def:registry_test>
    <win-def:registry_test id="oval:com.kaspersky.ics-cert:tst:5" check="all" check_existence="any_exist" version="1" comment="CIMPLICITY 8.2 SIM version less than SIM 27 installed">
      <win-def:object object_ref="oval:com.kaspersky.ics-cert:obj:9" />
      <win-def:state state_ref="oval:com.kaspersky.ics-cert:ste:3" />
    </win-def:registry_test>
    <win-def:registry_test id="oval:com.kaspersky.ics-cert:tst:6" check="at least one" version="1" comment="CIMPLICITY Windows services without DACLs">
      <win-def:object object_ref="oval:com.kaspersky.ics-cert:obj:3" />
      <win-def:state state_ref="oval:com.kaspersky.ics-cert:ste:6" />
    </win-def:registry_test>
  </oval-def:tests>
  <oval-def:objects>
    <win-def:registry_object id="oval:com.kaspersky.ics-cert:obj:1" comment="CIMPLICITY Version x32 view" version="1">
      <win-def:behaviors windows_view="32_bit" />
      <win-def:hive>HKEY_LOCAL_MACHINE</win-def:hive>
      <win-def:key operation="pattern match" var_ref="oval:com.kaspersky.ics-cert:var:4" />
      <win-def:name>DisplayVersion</win-def:name>
    </win-def:registry_object>
    <win-def:registry_object id="oval:com.kaspersky.ics-cert:obj:2" comment="CIMPLICITY SIM Version x32 view" version="1">
      <win-def:behaviors windows_view="32_bit" />
      <win-def:hive>HKEY_LOCAL_MACHINE</win-def:hive>
      <win-def:key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\{D33BB924-C487-4065-8B5A-DD9C900000\d{2}\}$</win-def:key>
      <win-def:name>DisplayVersion</win-def:name>
    </win-def:registry_object>
    <win-def:registry_object id="oval:com.kaspersky.ics-cert:obj:3" comment="CIMPLICITY services security descriptors" version="1">
      <win-def:hive>HKEY_LOCAL_MACHINE</win-def:hive>
      <win-def:key operation="pattern match">^SYSTEM\\CurrentControlSet\\services\\((CIMPLICITY)|(WEBVIEW)|(EGD Service)|(CimProxy))\\Security$</win-def:key>
      <win-def:name>Security</win-def:name>
    </win-def:registry_object>
    <win-def:registry_object id="oval:com.kaspersky.ics-cert:obj:6" comment="CIMPLICITY Version x64 view" version="1">
      <win-def:behaviors windows_view="64_bit" />
      <win-def:hive>HKEY_LOCAL_MACHINE</win-def:hive>
      <win-def:key operation="pattern match" var_ref="oval:com.kaspersky.ics-cert:var:4" />
      <win-def:name>DisplayVersion</win-def:name>
    </win-def:registry_object>
    <win-def:registry_object id="oval:com.kaspersky.ics-cert:obj:7" comment="CIMPLICITY Version" version="1">
      <oval-def:set set_operator="UNION">
        <oval-def:object_reference>oval:com.kaspersky.ics-cert:obj:1</oval-def:object_reference>
        <oval-def:object_reference>oval:com.kaspersky.ics-cert:obj:6</oval-def:object_reference>
      </oval-def:set>
    </win-def:registry_object>
    <win-def:registry_object id="oval:com.kaspersky.ics-cert:obj:8" comment="CIMPLICITY SIM Version x64 view" version="1">
      <win-def:behaviors windows_view="64_bit" />
      <win-def:hive>HKEY_LOCAL_MACHINE</win-def:hive>
      <win-def:key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\{D33BB924-C487-4065-8B5A-DD9C900000\d{2}\}$</win-def:key>
      <win-def:name>DisplayVersion</win-def:name>
    </win-def:registry_object>
    <win-def:registry_object id="oval:com.kaspersky.ics-cert:obj:9" comment="CIMPLICITY SIM Version" version="1">
      <oval-def:set set_operator="UNION">
        <oval-def:object_reference>oval:com.kaspersky.ics-cert:obj:2</oval-def:object_reference>
        <oval-def:object_reference>oval:com.kaspersky.ics-cert:obj:8</oval-def:object_reference>
      </oval-def:set>
    </win-def:registry_object>
  </oval-def:objects>
  <oval-def:states>
    <win-def:registry_state id="oval:com.kaspersky.ics-cert:ste:1" version="1" comment="CIMPLICITY version less than CIMPLICITY 8.1">
      <win-def:value datatype="version" operation="less than">8.10.18236</win-def:value>
    </win-def:registry_state>
    <win-def:registry_state id="oval:com.kaspersky.ics-cert:ste:2" version="1" comment="CIMPLICITY version less than CIMPLICITY 8.1 SIM 29">
      <win-def:value datatype="version" operation="less than">8.10.18651</win-def:value>
    </win-def:registry_state>
    <win-def:registry_state id="oval:com.kaspersky.ics-cert:ste:3" version="1" comment="CIMPLICITY version less than CIMPLICITY 8.2 SIM 27">
      <win-def:value datatype="version" operation="less than">8.20.20570</win-def:value>
    </win-def:registry_state>
    <win-def:registry_state id="oval:com.kaspersky.ics-cert:ste:4" version="1" comment="CIMPLICITY 8.1">
      <win-def:value datatype="version">8.10.18236</win-def:value>
    </win-def:registry_state>
    <win-def:registry_state id="oval:com.kaspersky.ics-cert:ste:5" version="1" comment="CIMPLICITY 8.2">
      <win-def:value datatype="version">8.20.20313</win-def:value>
    </win-def:registry_state>
    <win-def:registry_state id="oval:com.kaspersky.ics-cert:ste:6" version="1" comment="Windows service has default DACLs">
      <win-def:type>reg_binary</win-def:type>
      <win-def:value datatype="binary">01001480300000003C000000140000000000000002001C000100000002801400FF010F00010100000000000100000000010100000000000512000000010100000000000512000000</win-def:value>
    </win-def:registry_state>
  </oval-def:states>
  <oval-def:variables>
    <oval-def:constant_variable id="oval:com.kaspersky.ics-cert:var:4" version="1" comment="CIMPLICITY registry key" datatype="string">
      <oval-def:value>^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{((4AF366C7-81ED-420E-9B1E-6CBF8F96E722)|(C596BAFB-9F7B-4042-B765-660902CD2F05))}$</oval-def:value>
    </oval-def:constant_variable>
  </oval-def:variables>
</oval-def:oval_definitions>