First published: Sat Jan 17 2015(Updated: )
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier allow remote attackers to cause a denial of service (resource consumption or reboot) via crafted packets.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Ge Multilink ML810 Firmware | <=5.2.0 | |
Ge Multilink ML810 Firmware | ||
Ge Multilink ML1600 Firmware | <=4.2.1 | |
Ge Multilink ML1600 Firmware | ||
GE Multilink ML1200 Firmware | <=4.2.1 | |
GE Multilink ML1200 Firmware | ||
GE Multilink ML3000 | <=5.2.0 | |
Ge Multilink Ml3000 Firmware | ||
GE Multilink ML2400 | <=4.2.1 | |
Ge Multilink Ml2400 Firmware | ||
Ge Multilink ML3100 Firmware | <=5.2.0 | |
GE Multilink ML3100 | ||
Ge Multilink ML800 Firmware | <=4.2.1 | |
Ge Multilink ML800 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5418 has a severity rating that indicates a moderate risk due to its potential to cause a denial of service.
To fix CVE-2014-5418, upgrade the firmware of the affected GE Multilink switches to versions later than 4.2.1 or 5.2.0, as appropriate.
CVE-2014-5418 affects GE Multilink ML800, ML1200, ML1600, ML2400, ML810, ML3000, and ML3100 switches running specific firmware versions.
Yes, CVE-2014-5418 allows remote attackers to exploit the vulnerability and potentially cause service disruptions.
The potential impacts of CVE-2014-5418 include resource consumption and unintentional reboots of affected switches.