A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06 that could allow an authenticated remote attacker to execute arbitrary code on the system.
2022-03-18T18:15:09.417
2024-11-21T05:17:37.293
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | ge | rt430_firmware | < 08a06 | Yes |
Hardware | ge | rt430 | - | No |
Operating System | ge | rt431_firmware | < 08a06 | Yes |
Hardware | ge | rt431 | - | No |
Operating System | ge | rt434_firmware | < 08a06 | Yes |
Hardware | ge | rt434 | - | No |