CVE-2018-10613
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior.
Affected (2)
Products: Ge: Mds Pulsenet
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.2.1 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.2.1 |
References (6)
Source: ics-cert@hq.dhs.gov
Permissions Required
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.