7.8

CVE-2018-8867

In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 and prior, PACSystems RSTi-EP CPE 100 all versions, and PACSystems CPU320/CRU320 RXi all versions, the device does not properly validate input, which could allow a remote attacker to send specially crafted packets causing the device to become unavailable.

Data is provided by the National Vulnerability Database (NVD)
GePacsystems Rx3i Cpe305 Firmware Version <= 9.20
   GePacsystems Rx3i Cpe305 Version-
GePacsystems Rx3i Cpe310 Firmware Version <= 9.20
   GePacsystems Rx3i Cpe310 Version-
GeRx3i Cpe330 Firmware Version <= 9.21
   GeRx3i Cpe330 Version-
GeRx3i Cpe 400 Firmware Version <= 9.30
   GeRx3i Cpe 400 Version-
GePacsystems Cpu320 Firmware Version-
   GePacsystems Cpu320 Version-
GePacsystems Cru320 Firmware Version-
   GePacsystems Cru320 Version-
GePacsystems Rxi Firmware Version-
   GePacsystems Rxi Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.07% 0.829
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.