SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-4732

cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms allows remote authenticated administrators to execute arbitrary code…

HIGH 9.0EPSS 4.51%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (4.51%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms allows remote authenticated administrators to execute arbitrary code by using a config.html 2.conf action to replace the logo page's GIF image file with a file containing this code, a different vulnerability than CVE-2009-4463.

CVSS 2.0
9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS
4.51% probability · 91th percentile
CISA KEV
Not listed
Weakness
CWE-94
Affected
intellicom/netbiter easyconnect ec150 · intellicom/netbiter modbus rtu-tcp gateway mb100 · intellicom/netbiter serial ethernet server ss100 · intellicom/netbiter webscada ws100 · intellicom/netbiter webscada ws200 · intellicom/netbiter nb100 · intellicom/netbiter nb200
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.