SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-5418

GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier allow remote attackers to cause a denial of service (resource consumption or reboot)…

HIGH 7.8EPSS 3.19%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.19%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier allow remote attackers to cause a denial of service (resource consumption or reboot) via crafted packets.

CVSS 2.0
7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
EPSS
3.19% probability · 87th percentile
CISA KEV
Not listed
Weakness
CWE-400, CWE-399
Affected
ge/multilink ml810 firmware · ge/multilink ml810 · ge/multilink ml1600 firmware · ge/multilink ml1600 · ge/multilink ml1200 firmware · ge/multilink ml1200 · ge/multilink ml3000 firmware · ge/multilink ml3000 · ge/multilink ml2400 firmware · ge/multilink ml2400 · ge/multilink ml3100 firmware · ge/multilink ml3100 · ge/multilink ml800 firmware · ge/multilink ml800
Source
ics-cert@hq.dhs.gov

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.