5 results (0.003 seconds)

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

04 Jun 2018 — Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior. Podrían emplearse múltiples variantes de ataques XEE (XML External Entity) para exfiltrar datos de la plataforma host de Windows en GE MDS PulseNET y MDS PulseNET Enterprise en versiones 3.2.1 y anteriores. This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of GE MDS P... • http://www.gegridsolutions.com/app/DownloadFile.aspx?prod=pulsenet&type=9&file=1 • CWE-611: Improper Restriction of XML External Entity Reference •

CVSS: 9.8EPSS: 4%CPEs: 2EXPL: 0

04 Jun 2018 — Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to allow unauthenticated users to launch applications and support remote code execution through web services. El puerto de entradas Java RMI (Remote Method Invocation) en GE MDS PulseNET y MDS PulseNET Enterprise, en versiones 3.2.1 y anteriores, podría explotarse para permitir que usuarios no autenticados lancen aplicaciones y soporten la ejecución remota de código mediante... • http://www.gegridsolutions.com/app/DownloadFile.aspx?prod=pulsenet&type=9&file=1 • CWE-287: Improper Authentication •

CVSS: 8.1EPSS: 0%CPEs: 2EXPL: 0

04 Jun 2018 — Directory traversal may lead to files being exfiltrated or deleted on the GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior host platform. Un salto de directorio podría conducir a que los archivos se exfiltren o eliminen de GE MDS PulseNET y MDS PulseNET Enterprise en versiones 3.2.1 y anteriores. This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of GE MDS PulseNET. Although authentication is required to exploit this vulnerability, the... • http://www.gegridsolutions.com/app/DownloadFile.aspx?prod=pulsenet&type=9&file=1 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-23: Relative Path Traversal •

CVSS: 10.0EPSS: 31%CPEs: 2EXPL: 0

16 Sep 2015 — Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 allows remote attackers to read or delete arbitrary files via a full pathname. Vulnerabilidad de salto de ruta absoluta en la funcionalidad de descarga en FileDownloadServlet en GE Digital Energy MDS PulseNET y MDS PulseNET Enterprise en versiones anteriores a 3.1.5, permite a atacantes remotos leer o eliminar archivos arbitrarios a través de un nomb... • http://www.gedigitalenergy.com/app/resources.aspx?prod=pulsenet&type=9 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 9.8EPSS: 5%CPEs: 2EXPL: 0

16 Sep 2015 — GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 have hardcoded credentials for a support account, which allows remote attackers to obtain administrative access, and consequently execute arbitrary code, by leveraging knowledge of the password. Vulnerabilidad en GE Digital Energy MDS PulseNET y MDS PulseNET Enterprise en versiones anteriores a 3.1.5, tienen credenciales embebidos para la cuenta de soporte, lo que permite a atacantes remotos obtener acceso adminitrativo, y consecuenteme... • http://www.gedigitalenergy.com/app/resources.aspx?prod=pulsenet&type=9 •