PT-2021-19358 · Ge · Ge Reason Rpv311

Published

2021-05-27

·

Updated

2021-06-24

·

CVE-2021-31477

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GE Reason RPV311 version 14A03
Description This issue allows remote attackers to execute arbitrary code on affected installations. Authentication is not required to exploit this issue. The specific flaw exists within the firmware and filesystem of the device, which contain hard-coded default credentials. An attacker can leverage this issue to execute code in the context of the download user.
Recommendations For GE Reason RPV311 version 14A03, consider changing the hard-coded default credentials to prevent exploitation. As a temporary workaround, restrict access to the device to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-31477
ZDI-21-616

Affected Products

Ge Reason Rpv311