Vulnerabilities > CVE-2015-6456 - Unspecified vulnerability in GE MDS Pulsenet 3.0.0/3.0.1/3.1.3
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 have hardcoded credentials for a support account, which allows remote attackers to obtain administrative access, and consequently execute arbitrary code, by leveraging knowledge of the password.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |
References
- http://www.gedigitalenergy.com/app/resources.aspx?prod=pulsenet&type=9
- http://www.gedigitalenergy.com/app/resources.aspx?prod=pulsenet&type=9
- http://zerodayinitiative.com/advisories/ZDI-15-440/
- http://zerodayinitiative.com/advisories/ZDI-15-440/
- https://ics-cert.us-cert.gov/advisories/ICSA-15-258-03
- https://ics-cert.us-cert.gov/advisories/ICSA-15-258-03