PT-2019-18156 · Ge+1 · Ge Communicator+1
Reid Wightman
·
Published
2019-05-09
·
Updated
2020-10-16
·
CVE-2019-6544
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GE Communicator versions prior to 4.0.517
Description
The issue allows an unprivileged user to perform certain administrative actions, potentially enabling the execution of scheduled scripts with system administrator privileges. This is due to a service running with system privileges. However, the service is inaccessible to attackers if Windows default firewall settings are used.
Recommendations
For GE Communicator versions prior to 4.0.517, update to version 4.0.517 or later to resolve the issue. As a temporary workaround, consider using Windows default firewall settings to restrict access to the vulnerable service.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ge Communicator
Windows