VulnerabilityModified
CVE-2018-9115
An attacker can freeze the Situational Layer, which means that the Situational Picture is no longer updated.
MEDIUM 5.3EPSS 5.90%
Does this matter?
Lower severity and a low EPSS score (5.90%). Track it; it rarely justifies an emergency change on its own.
Description
Systematic SitaWare 6.4 SP2 does not validate input from other sources sufficiently. e.g., information utilizing the NVG interface. An attacker can freeze the Situational Layer, which means that the Situational Picture is no longer updated. Unfortunately, the user cannot notice until he tries to work with that layer.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 5.90% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- systematicinc/sitaware
- Source
- cve@mitre.org
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/141099VDB Entry
- https://packetstormsecurity.com/files/146982Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/44375/Exploit, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/141099VDB Entry
- https://packetstormsecurity.com/files/146982Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/44375/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.