PT-2019-18156 · Ge+1 · Ge Communicator+1

Reid Wightman

·

Published

2019-05-09

·

Updated

2020-10-16

·

CVE-2019-6544

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GE Communicator versions prior to 4.0.517
Description The issue allows an unprivileged user to perform certain administrative actions, potentially enabling the execution of scheduled scripts with system administrator privileges. This is due to a service running with system privileges. However, the service is inaccessible to attackers if Windows default firewall settings are used.
Recommendations For GE Communicator versions prior to 4.0.517, update to version 4.0.517 or later to resolve the issue. As a temporary workaround, consider using Windows default firewall settings to restrict access to the vulnerable service.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-6544

Affected Products

Ge Communicator
Windows