QID 591284
Date Published: 2023-01-13
QID 591284: General Electric Multilink Switch Rivest Shamir Adleman (RSA) Private Key and Denial of Service (DoS) Multiple Vulnerabilities (ICSA-15-013-04A)
AFFECTED PRODUCTS
GE Multilink ML800/1200/1600/2400 Version 4.2.1and prior.
GE Multilink ML810/3000/3100 series switch Version 5.2.0 and prior.
QID Detection Logic:
This QID checks for the Vulnerable version of General Electric Multilink Switch using passive scanning
The GE Multilink ML800 is subject to unauthorized access via hard-coded credentials. In addition, availability can be impacted through attacks composed of specifically crafted packets to the web server resulting in switch performance degradation. If attacks continue, the web server will be subject to a denial of service. The cross-site scripting vulnerability could inject content into response pages from the web interface, allowing a malicious user to deliver unknown and potentially malicious scripts to other users of the web interface.
Customers are advised to refer to CERT MITIGATIONS section ICSA-15-013-04A for affected packages and patching details.
- ICSA-15-013-04A -
www.cisa.gov/uscert/ics/advisories/ICSA-15-013-04A
CVEs related to QID 591284
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-15-013-04A |
|