First published: Wed Jul 10 2019(Updated: )
In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to a TCP/IP network configuration, which could allow an attacker to remotely modify device configuration and silence alarms.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
GE Aestiva 7100 | ||
GE Aestiva 7100 | ||
GE Aestiva 7900 | ||
GE Aestiva 7900 | ||
GE Aespire 7100 | ||
Ge Aespire 7100 Firmware | ||
GE Aespire 7900 | ||
GE Aespire 7900 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10966 is categorized as a critical vulnerability due to the potential for remote configuration changes and alarm silencing.
To fix CVE-2019-10966, ensure that the terminal server is secured and restrict access to the TCP/IP network.
CVE-2019-10966 affects the GE Aestiva and Aespire systems, specifically versions 7100 and 7900.
Yes, CVE-2019-10966 can be exploited remotely due to an unsecured terminal server configuration.
The potential impacts of CVE-2019-10966 include unauthorized modification of device configurations and the ability to silence alarms.