CVE-2015-6456: Critical severity ge mds pulsenet vulnerability
GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 have hardcoded credentials for a support account, which allows remote attackers to obtain administrative access, and consequently execute arbitrary code, by leveraging knowledge of the password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6456?
CVE-2015-6456 has been classified as a critical vulnerability due to hardcoded credentials that allow remote attackers to gain administrative access.
How can I fix CVE-2015-6456?
To fix CVE-2015-6456, upgrade to GE MDS PulseNET version 3.1.5 or later to eliminate the hardcoded credentials.
Which versions of GE MDS PulseNET are affected by CVE-2015-6456?
CVE-2015-6456 affects GE MDS PulseNET versions prior to 3.1.5.
What type of vulnerability is CVE-2015-6456?
CVE-2015-6456 is a remote code execution vulnerability due to hardcoded credentials in the software.
Who can exploit CVE-2015-6456?
Any remote attacker with knowledge of the hardcoded password can exploit CVE-2015-6456 to obtain administrative access.