CVE-2019-13524
GE PACSystems RX3i CPE100/115: All versions prior to R9.85,CPE302/305/310/330/400/410: All versions prior to R9.90,CRU/320 All versions(End of Life) may allow an attacker sending specially manipulated packets to cause the module state to change to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.55%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
GE PACSystems RX3i CPE100/115: All versions prior to R9.85,CPE302/305/310/330/400/410: All versions prior to R9.90,CRU/320 All versions(End of Life) may allow an attacker sending specially manipulated packets to cause the module state to change to halt-mode, resulting in a denial-of-service condition. An operator must reboot the CPU module after removing battery or energy pack to recover from halt-mode.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.55% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- emerson/rx3i cpe100 firmware · emerson/rx3i cpe115 firmware · emerson/rx3i cpe302 firmware · emerson/rx3i cpe305 firmware · emerson/rx3i cpe310 firmware · emerson/rx3i cru320 firmware · emerson/rx3i cpe330 firmware · emerson/rx3i cpe400 firmware · emerson/rx3i cpl410 firmware
- Source
- ics-cert@hq.dhs.gov
References
- https://www.us-cert.gov/ics/advisories/icsa-20-014-01Patch, Third Party Advisory, US Government Resource
- https://www.us-cert.gov/ics/advisories/icsa-20-014-01Patch, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.