In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to a TCP/IP network configuration, which could allow an attacker to remotely modify device configuration and silence alarms.
2019-07-10T18:15:10.817
2024-11-21T04:20:15.650
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | ge | aestiva_7100_firmware | - | Yes |
Hardware | ge | aestiva_7100 | - | No |
Operating System | ge | aestiva_7900_firmware | - | Yes |
Hardware | ge | aestiva_7900 | - | No |
Operating System | ge | aespire_7100_firmware | - | Yes |
Hardware | ge | aespire_7100 | - | No |
Operating System | ge | aespire_7900_firmware | - | Yes |
Hardware | ge | aespire_7900 | - | No |