PT-2021-19358 · Ge · Ge Reason Rpv311
Published
2021-05-27
·
Updated
2021-06-24
·
CVE-2021-31477
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GE Reason RPV311 version 14A03
Description
This issue allows remote attackers to execute arbitrary code on affected installations. Authentication is not required to exploit this issue. The specific flaw exists within the firmware and filesystem of the device, which contain hard-coded default credentials. An attacker can leverage this issue to execute code in the context of the download user.
Recommendations
For GE Reason RPV311 version 14A03, consider changing the hard-coded default credentials to prevent exploitation. As a temporary workaround, restrict access to the device to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ge Reason Rpv311