Описание
In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to a TCP/IP network configuration, which could allow an attacker to remotely modify device configuration and silence alarms.
Ссылки
- Third Party AdvisoryVDB Entry
- MitigationThird Party AdvisoryUS Government Resource
- Third Party AdvisoryVDB Entry
- MitigationThird Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:ge:aestiva_7100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:aestiva_7100:-:*:*:*:*:*:*:*
Конфигурация 2
Одновременно
cpe:2.3:o:ge:aestiva_7900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:aestiva_7900:-:*:*:*:*:*:*:*
Конфигурация 3
Одновременно
cpe:2.3:o:ge:aespire_7100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:aespire_7100:-:*:*:*:*:*:*:*
Конфигурация 4
Одновременно
cpe:2.3:o:ge:aespire_7900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:aespire_7900:-:*:*:*:*:*:*:*
EPSS
Процентиль: 54%
0.00311
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-287
CWE-287
Связанные уязвимости
github
больше 3 лет назад
In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to a TCP/IP network configuration, which could allow an attacker to remotely modify device configuration and silence alarms.
EPSS
Процентиль: 54%
0.00311
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-287
CWE-287