CVE-2018-8867: Input Validation
In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 and prior, PACSystems RSTi-EP CPE 100 all versions, and PACSystems CPU320/CRU320 RXi all versions, the device does not properly validate input, which could allow a remote attacker to send specially crafted packets causing the device to become unavailable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8867?
CVE-2018-8867 is classified as a high severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2018-8867?
To fix CVE-2018-8867, upgrade the affected firmware versions to the latest releases that address the input validation issue.
What are the affected versions in CVE-2018-8867?
CVE-2018-8867 affects GE PACSystems RX3i CPE305, CPE310, CPE330, CPE400, RSTi-EP CPE 100, and CPU320/CRU320 devices running specified versions prior to their secure updates.
Can CVE-2018-8867 be exploited remotely?
Yes, CVE-2018-8867 can be exploited remotely due to inadequate input validation.
What types of devices are impacted by CVE-2018-8867?
CVE-2018-8867 impacts industrial control system devices such as PACSystems RX3i and RSTi-EP series.