#VU13123 XXE attack in MDS PulseNET Enterprise and GE MDS PulseNET


Published: 2018-06-01

Vulnerability identifier: #VU13123

Vulnerability risk: Low

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2018-10613

CWE-ID: CWE-611

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
MDS PulseNET Enterprise
Web applications / Remote management & hosting panels
GE MDS PulseNET
Web applications / Remote management & hosting panels

Vendor: GE

Description
The vulnerability allows a remote unauthenticated attacker to perform XXE attack on the target system.

The weakness exists due to insufficient validation for external entities. A remote attacker can supply data containing an XML external entities, perform multiple variants of XXE attacks and exfiltrate data from the host Windows platform.

Mitigation
Install update from vendor's website.

Vulnerable software versions

MDS PulseNET Enterprise: All versions

GE MDS PulseNET: All versions


External links
http://ics-cert.us-cert.gov/advisories/ICSA-18-151-02


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability