VulnerabilityModified
CVE-2018-10613
Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior.
HIGH 7.5EPSS 18.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 18.1%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 18.06% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- ge/mds pulsenet
- Source
- ics-cert@hq.dhs.gov
References
- http://www.gegridsolutions.com/app/DownloadFile.aspx?prod=pulsenet&type=9&file=1Permissions Required
- http://www.securityfocus.com/bid/104377Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-151-02Third Party Advisory, US Government Resource
- http://www.gegridsolutions.com/app/DownloadFile.aspx?prod=pulsenet&type=9&file=1Permissions Required
- http://www.securityfocus.com/bid/104377Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-151-02Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.