PT-2018-10002 · Ge · Mds Pulsenet Enterprise+1
Rgod
·
Publicado
2018-06-04
·
Atualizado
2019-10-09
·
CVE-2018-10611
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior
Description
The issue allows unauthenticated users to launch applications and support remote code execution through web services. This is due to the deserialization of untrusted data in various services, including the Pooled Invoker, ToolingService, CommandLineService, and HealthCheck. The incorrect privilege assignment in the Account Java RMI also contributes to the problem.
Recommendations
For GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior, consider disabling the Java RMI input port and deserialization of untrusted data in the affected services as a temporary workaround until a patch is available.
Restrict access to the Pooled Invoker, ToolingService, CommandLineService, and HealthCheck services to minimize the risk of exploitation.
Avoid using the Account Java RMI until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ge Mds Pulsenet
Mds Pulsenet Enterprise