VulnerabilityModified
CVE-2018-8862
In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, an improper authentication vulnerability caused by specially crafted malicious radio transmissions may allow an attacker to remotely trigger false alarms.
LOW 3.1EPSS 0.58%
Does this matter?
Lower severity and a low EPSS score (0.58%). Track it; it rarely justifies an emergency change on its own.
Description
In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, an improper authentication vulnerability caused by specially crafted malicious radio transmissions may allow an attacker to remotely trigger false alarms.
- CVSS 3.0
- 3.1 LOWCVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.58% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- atisystem/hpss16 firmware · atisystem/hpss32 firmware · atisystem/mhpss firmware · atisystem/alert4000 firmware
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/103721Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-100-01Mitigation, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/103721Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-100-01Mitigation, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.