Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-19003


GE Mark VIe, EX2100e, EX2100e_Reg, and LS2100e Versions 03.03.28C to 05.02.04C, EX2100e All versions prior to v04.09.00C, EX2100e_Reg All versions prior to v04.09.00C, and LS2100e All versions prior to v04.09.00C The affected versions of the application have a path traversal vulnerability that fails to restrict the ability of an attacker to gain access to restricted information.


Published

2018-12-14T15:29:00.747

Last Modified

2024-11-21T03:57:08.707

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-22
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System ge ex2100e_firmware < 04.09.00c Yes
Operating System ge ex2100e - No
Operating System ge ls2100e_firmware < 04.09.00c Yes
Hardware ge ls2100e - No
Operating System ge ex2100e_firmware ≤ 05.02.04c Yes
Hardware ge ex2100e - No
Operating System ge ls2100e_firmware ≤ 05.02.04c Yes
Hardware ge ls2100e - No
Operating System ge mark_vle_firmware ≤ 05.02.04c Yes
Hardware ge mark_vle - No

References