CVE-2018-10613: XEE
Published Jun 4, 2018
·Updated
Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior.
Affected Software
2 affected components
GE MDS PulseNET<=3.2.1
GE MDS PulseNET<=3.2.1
Event History
Jun 4, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-10613?
CVE-2018-10613 is considered a high-severity vulnerability due to the potential for data exfiltration.
2
How do I fix CVE-2018-10613?
To fix CVE-2018-10613, upgrade GE MDS PulseNET or MDS PulseNET Enterprise to a version higher than 3.2.1.
3
What types of attacks are associated with CVE-2018-10613?
CVE-2018-10613 is associated with XML External Entity (XXE) attacks.
4
Which versions of GE MDS PulseNET are affected by CVE-2018-10613?
Versions of GE MDS PulseNET and MDS PulseNET Enterprise up to and including 3.2.1 are affected by CVE-2018-10613.
5
What impact does CVE-2018-10613 have on the system?
CVE-2018-10613 can allow attackers to exfiltrate sensitive data from the host Windows platform.