PT-2020-9404 · Ge · Ge Pacsystems Rx3I Cpe100/115+2
Jin Kyung Lee
+1
·
Published
2020-01-16
·
Updated
2020-01-27
·
CVE-2019-13524
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
GE PACSystems RX3i CPE100/115 versions prior to R9.85
GE PACSystems RX3i CPE302/305/310/330/400/410 versions prior to R9.90
GE PACSystems RX3i CRU/320 (all versions)
Description:
The issue allows an attacker to send specially manipulated packets, causing the module state to change to halt-mode. This results in a denial-of-service condition. To recover from halt-mode, an operator must reboot the CPU module after removing the battery or energy pack.
Recommendations:
For GE PACSystems RX3i CPE100/115 versions prior to R9.85, update to version R9.85 or later.
For GE PACSystems RX3i CPE302/305/310/330/400/410 versions prior to R9.90, update to version R9.90 or later.
For GE PACSystems RX3i CRU/320, since all versions are affected and it is end-of-life, consider replacing the module with a supported version.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ge Pacsystems Rx3I Cpe100/115
Ge Pacsystems Rx3I Cpe302/305/310/330/400/410
Ge Pacsystems Rx3I Cru/320