QID 591321
Date Published: 2023-02-03
QID 591321: General Electric MultiLink Managed Switches Hard-coded Credentials Vulnerability (GET-20042)
AFFECTED PRODUCTS
ML800/1200/1600/2400
ML810/3000/3100
QID Detection Logic:
This QID checks for the Vulnerable version of General Electric MultiLink Managed Switches using passive scanning
GE has received and confirmed a report about a hard-coded credential within the ML800 that could be used tobypass the web configuration access controls. This vulnerability could allow a user to gain administrative access to the device configuration resulting in exposure and control of all configuration options available through the web interface. The vulnerability has been resolved by removing of the hard-coded credentials in firmware version 5.5.0.
Customers are advised to refer to GE MITIGATIONS section GET-20042 for affected packages and patching details.
CVEs related to QID 591321
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GET-20042 |
|