CVE-2020-25197: GE Reason RT43X Clocks Code Injection
A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06 that could allow an authenticated remote attacker to execute arbitrary code on the system.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-25197?
CVE-2020-25197 is a code injection vulnerability that exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06.
What is the severity of CVE-2020-25197?
CVE-2020-25197 has a severity rating of 8.8 (critical).
How can an attacker exploit CVE-2020-25197?
An authenticated remote attacker can exploit CVE-2020-25197 to execute arbitrary code on the system.
Which software versions are affected by CVE-2020-25197?
Firmware versions prior to 08A06 of GE Reason RT430, RT431 & RT434 GNSS clocks are affected by CVE-2020-25197.
Where can I find more information about CVE-2020-25197?
You can find more information about CVE-2020-25197 at the following references: [Reference 1](https://www.cisa.gov/uscert/ics/advisories/icsa-21-005-03), [Reference 2](https://www.gegridsolutions.com/app/DownloadFile.aspx?prod=RT430&type=21&file=5).