9
CVE-2015-6456
- EPSS 2.39%
- Veröffentlicht 18.09.2015 22:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 have hardcoded credentials for a support account, which allows remote attackers to obtain administrative access, and consequently execute arbitrary code, by leveraging knowledge of the password.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ge ≫ Mds Pulsenet Version <= 3.1.3
Ge ≫ Mds Pulsenet SwEditionenterprise Version <= 3.1.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.39% | 0.835 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9 | 8 | 10 |
AV:N/AC:L/Au:S/C:C/I:C/A:C
|