PT-2018-18677 · Ge · Ge Pacsystems Rx3I Cpe305/310+4
Younes Dragoni
·
Published
2018-05-18
·
Updated
2019-10-09
·
CVE-2018-8867
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
GE PACSystems RX3i CPE305/310 versions 9.20 and prior
GE PACSystems RX3i CPE330 version 9.21 and prior
GE PACSystems RX3i CPE 400 version 9.30 and prior
GE PACSystems RSTi-EP CPE 100 all versions
GE PACSystems CPU320/CRU320 RXi all versions
Description
The device does not properly validate input, which could allow a remote attacker to send specially crafted packets causing the device to become unavailable.
Recommendations
For GE PACSystems RX3i CPE305/310 versions 9.20 and prior, update to a version later than 9.20.
For GE PACSystems RX3i CPE330 version 9.21 and prior, update to a version later than 9.21.
For GE PACSystems RX3i CPE 400 version 9.30 and prior, update to a version later than 9.30.
For GE PACSystems RSTi-EP CPE 100 all versions, consider implementing additional security measures to prevent remote attacks.
For GE PACSystems CPU320/CRU320 RXi all versions, consider implementing additional security measures to prevent remote attacks.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ge Pacsystems Cpu320/Cru320 Rxi
Ge Pacsystems Rsti-Ep Cpe 100
Ge Pacsystems Rx3I Cpe 400
Ge Pacsystems Rx3I Cpe305/310
Ge Pacsystems Rx3I Cpe330