Missing Authentication for Critical Function in GE Grid Solutions Reason RT Clocks



Published: 2020-06-03
Risk Medium
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2020-12017
CWE-ID CWE-306
Exploitation vector Local network
Public exploit N/A
Vulnerable software
Subscribe
Reason RT430
Hardware solutions / Other hardware appliances

Reason RT431
Hardware solutions / Other hardware appliances

Reason RT434
Hardware solutions / Other hardware appliances

Vendor GE

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Missing Authentication for Critical Function

EUVDB-ID: #VU28548

Risk: Medium

CVSSv3.1: 8.3 [CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2020-12017

CWE-ID: CWE-306 - Missing Authentication for Critical Function

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to an insufficient authentication mechanism in the web application. A remote attacker on the local network can send a specially crafted request to execute arbitrary commands, change the password of the "configuration" user account to modify the configuration of the device, or bypass the authentication required to configure the device and reboot the system. 

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Reason RT430: before 08A05

Reason RT431: before 08A05

Reason RT434: before 08A05

External links

http://www.us-cert.gov/ics/advisories/icsa-20-154-05
http://www.gegridsolutions.com/app/ViewFiles.aspx?prod=RT430&type=7


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###