cbcvebase.

Ge Mds Pulsenet vulnerabilities

5 known vulnerabilities affecting ge/mds_pulsenet.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH2

Vulnerabilities

Page 1 of 1
CVE-2018-10611P2CRITICALCVSS 9.8≤ 3.2.12018-06-04
CVE-2018-10611 [CRITICAL] CWE-287 CVE-2018-10611: Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise versio Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to allow unauthenticated users to launch applications and support remote code execution through web services.
nvd
CVE-2015-6456P3CRITICALCVSS 9.0≤ 3.1.32015-09-18
CVE-2015-6456 [CRITICAL] CVE-2015-6456: GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 have hardcoded credentials f GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 have hardcoded credentials for a support account, which allows remote attackers to obtain administrative access, and consequently execute arbitrary code, by leveraging knowledge of the password.
nvd
CVE-2018-10613P3HIGHCVSS 7.5≤ 3.2.12018-06-04
CVE-2018-10613 [HIGH] CWE-611 CVE-2018-10613: Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior.
nvd
CVE-2015-6459P3CRITICALCVSS 10.0≤ 3.1.32015-09-18
CVE-2015-6459 [CRITICAL] CWE-22 CVE-2015-6459: Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital E Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 allows remote attackers to read or delete arbitrary files via a full pathname.
nvd
CVE-2018-10615P3HIGHCVSS 8.1≤ 3.2.12018-06-04
CVE-2018-10615 [HIGH] CWE-23 CVE-2018-10615: Directory traversal may lead to files being exfiltrated or deleted on the GE MDS PulseNET and MDS Pu Directory traversal may lead to files being exfiltrated or deleted on the GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior host platform.
nvd
Ge Mds Pulsenet vulnerabilities | cvebase