CVE-2019-10966
Published Jul 10, 2019
Last updated 4 years ago
Overview
- Description
- In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to a TCP/IP network configuration, which could allow an attacker to remotely modify device configuration and silence alarms.
- Source
- ics-cert@hq.dhs.gov
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 5.3
- Impact score
- 1.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:P/A:N
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:ge:aestiva_7100_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F3B952A1-941D-4001-B73C-7F0111BF1956" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:ge:aestiva_7100:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F447B046-1ACE-4ACC-9316-E9FECFCA1EBB" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:ge:aestiva_7900_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0961C975-4C72-48B4-A0D7-6CB9E8B32789" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:ge:aestiva_7900:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "167A5605-7871-4A21-8818-B0419D791F8E" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:ge:aespire_7100_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "079FA27D-5F79-4549-A2D7-2F47B5B03B42" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:ge:aespire_7100:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9F0B78FB-1693-4C3B-9AC2-B330909F6A29" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:ge:aespire_7900_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "58BD99AD-CD5A-43E1-B6FD-CA2FD6577DB5" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:ge:aespire_7900:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6F133CC4-BCB0-4B82-BE4B-1B27F1E6DD3D" } ], "operator": "OR" } ], "operator": "AND" } ]