PT-2020-9407 · Ge · Ge Mark Vie Controller

Published

2020-04-07

·

Updated

2020-10-09

·

CVE-2019-13554

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: GE Mark VIe Controller (affected versions not specified)
Description: The issue concerns an unsecured Telnet protocol that may allow a user to create an authenticated session using generic default credentials. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations: Disable the Telnet service to mitigate the risk.

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-13554

Affected Products

Ge Mark Vie Controller