35
CVE-2019-10966
—CVSS 3.1
5.3 medium
EPSS
1%p70
Published
()
Modified
Description
In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to a TCP/IP network configuration, which could allow an attacker to remotely modify device configuration and silence alarms.
- Vendors
- ge
- Products
- aestiva 7100 firmware, aestiva 7900 firmware, aespire 7100 firmware, aespire 7900 firmware
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N