CVE-2014-5418
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier allow remote attackers to cause a denial of service (resource consumption or reboot)…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.19%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier allow remote attackers to cause a denial of service (resource consumption or reboot) via crafted packets.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 3.19% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400, CWE-399
- Affected
- ge/multilink ml810 firmware · ge/multilink ml810 · ge/multilink ml1600 firmware · ge/multilink ml1600 · ge/multilink ml1200 firmware · ge/multilink ml1200 · ge/multilink ml3000 firmware · ge/multilink ml3000 · ge/multilink ml2400 firmware · ge/multilink ml2400 · ge/multilink ml3100 firmware · ge/multilink ml3100 · ge/multilink ml800 firmware · ge/multilink ml800
- Source
- ics-cert@hq.dhs.gov
References
- http://www.gedigitalenergy.com/products/support/multilink/MLSB1214.pdfVendor Advisory
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2015/icsa-15-013-04a.json
- https://www.cisa.gov/news-events/ics-advisories/icsa-15-013-04a
- http://www.gedigitalenergy.com/products/support/multilink/MLSB1214.pdfVendor Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-15-013-04Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.