PT-2018-10002 · Ge · Mds Pulsenet Enterprise+1
Rgod
·
Published
2018-06-04
·
Updated
2019-10-09
·
CVE-2018-10611
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior
Description
The issue allows unauthenticated users to launch applications and support remote code execution through web services. This is due to the deserialization of untrusted data in various services, including the Pooled Invoker, ToolingService, CommandLineService, and HealthCheck. The incorrect privilege assignment in the Account Java RMI also contributes to the problem.
Recommendations
For GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior, consider disabling the Java RMI input port and deserialization of untrusted data in the affected services as a temporary workaround until a patch is available.
Restrict access to the Pooled Invoker, ToolingService, CommandLineService, and HealthCheck services to minimize the risk of exploitation.
Avoid using the Account Java RMI until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ge Mds Pulsenet
Mds Pulsenet Enterprise