CVE-2018-10611
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to allow unauthenticated users to launch applications and support remote code execution through web services.
Affected (2)
Products: Ge: Mds Pulsenet
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.2.1 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.2.1 |
References (6)
Source: ics-cert@hq.dhs.gov
Permissions Required
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.