CVE-2020-25197
A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06 that could allow an authenticated remote attacker to execute arbitrary code on the system.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06 that could allow an authenticated remote attacker to execute arbitrary code on the system.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.17% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- ge/rt430 firmware · ge/rt431 firmware · ge/rt434 firmware
- Source
- ics-cert@hq.dhs.gov
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-005-03Mitigation, Third Party Advisory, US Government Resource
- https://www.gegridsolutions.com/app/DownloadFile.aspx?prod=RT430&type=21&file=5Permissions Required
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-005-03Mitigation, Third Party Advisory, US Government Resource
- https://www.gegridsolutions.com/app/DownloadFile.aspx?prod=RT430&type=21&file=5Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.