Code Injection in GE products - CVE-2020-25197

 

Code Injection in GE products - CVE-2020-25197

Published: January 6, 2021


Vulnerability identifier: #VU49294
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-25197
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation. A remote attacker can send a specially crafted request and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Reason RT430
Reason RT431
Reason RT434

How to mitigate CVE-2020-25197

Install updates from vendor's website.

Reason RT430 - update to 08A06
Reason RT431 - update to 08A06
Reason RT434 - update to 08A06

External References

Related Security Bulletins