ZeroHour

CVE-2019-10966

CVSS 3.1
5.3 medium
EPSS
1%p70
Published
()
Modified
Description

In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to a TCP/IP network configuration, which could allow an attacker to remotely modify device configuration and silence alarms.

Vendors
ge
Products
aestiva 7100 firmware, aestiva 7900 firmware, aespire 7100 firmware, aespire 7900 firmware
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news