// For flags

CVE-2019-10966

 

Severity Score

5.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to a TCP/IP network configuration, which could allow an attacker to remotely modify device configuration and silence alarms.

En Aestiva y Aespire de GE versiones 7100 y 7900, se presenta una vulnerabilidad donde los dispositivos seriales son conectados por medio de un servidor terminal no seguro agregado a una configuración de red TCP/IP, lo que podría permitir a un atacante modificar remotamente la configuración del dispositivo y silenciar las alarmas.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-04-08 CVE Reserved
  • 2019-07-10 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-11-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-287: Improper Authentication
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ge
Search vendor "Ge"
Aestiva 7100 Firmware
Search vendor "Ge" for product "Aestiva 7100 Firmware"
--
Affected
in Ge
Search vendor "Ge"
Aestiva 7100
Search vendor "Ge" for product "Aestiva 7100"
--
Safe
Ge
Search vendor "Ge"
Aestiva 7900 Firmware
Search vendor "Ge" for product "Aestiva 7900 Firmware"
--
Affected
in Ge
Search vendor "Ge"
Aestiva 7900
Search vendor "Ge" for product "Aestiva 7900"
--
Safe
Ge
Search vendor "Ge"
Aespire 7100 Firmware
Search vendor "Ge" for product "Aespire 7100 Firmware"
--
Affected
in Ge
Search vendor "Ge"
Aespire 7100
Search vendor "Ge" for product "Aespire 7100"
--
Safe
Ge
Search vendor "Ge"
Aespire 7900 Firmware
Search vendor "Ge" for product "Aespire 7900 Firmware"
--
Affected
in Ge
Search vendor "Ge"
Aespire 7900
Search vendor "Ge" for product "Aespire 7900"
--
Safe