PT-2018-17303 · Silex+1 · Silex Sx-500+1

Published

2018-05-09

·

Updated

2018-06-13

·

CVE-2018-6020

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Silex SX-500 versions all GE MobileLink version 1.54 and prior
Description The issue concerns authentication verification when making certain POST requests. Specifically, authentication is not properly verified, which may allow attackers to modify system settings.
Recommendations For Silex SX-500, update to a version that properly verifies authentication for all requests. For GE MobileLink version 1.54 and prior, update to a version that properly verifies authentication for all requests. As a temporary workaround, consider restricting access to the system settings until a patch is available.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-6020

Affected Products

Ge Mobilelink
Silex Sx-500