First published: Fri Sep 18 2015(Updated: )
GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 have hardcoded credentials for a support account, which allows remote attackers to obtain administrative access, and consequently execute arbitrary code, by leveraging knowledge of the password.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
GE MDS PulseNET | <=3.1.3 | |
GE MDS PulseNET | <=3.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6456 has been classified as a critical vulnerability due to hardcoded credentials that allow remote attackers to gain administrative access.
To fix CVE-2015-6456, upgrade to GE MDS PulseNET version 3.1.5 or later to eliminate the hardcoded credentials.
CVE-2015-6456 affects GE MDS PulseNET versions prior to 3.1.5.
CVE-2015-6456 is a remote code execution vulnerability due to hardcoded credentials in the software.
Any remote attacker with knowledge of the hardcoded password can exploit CVE-2015-6456 to obtain administrative access.