CVE-2019-13524
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
16/01/2020
Last modified:
27/01/2020
Description
GE PACSystems RX3i CPE100/115: All versions prior to R9.85,CPE302/305/310/330/400/410: All versions prior to R9.90,CRU/320 All versions(End of Life) may allow an attacker sending specially manipulated packets to cause the module state to change to halt-mode, resulting in a denial-of-service condition. An operator must reboot the CPU module after removing battery or energy pack to recover from halt-mode.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:emerson:rx3i_cpe100_firmware:*:*:*:*:*:*:*:* | r9.85 (excluding) | |
| cpe:2.3:h:emerson:rx3i_cpe100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:emerson:rx3i_cpe115_firmware:*:*:*:*:*:*:*:* | r9.85 (excluding) | |
| cpe:2.3:h:emerson:rx3i_cpe115:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:emerson:rx3i_cpe302_firmware:*:*:*:*:*:*:*:* | r9.90 (excluding) | |
| cpe:2.3:h:emerson:rx3i_cpe302:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:emerson:rx3i_cpe305_firmware:*:*:*:*:*:*:*:* | r9.90 (excluding) | |
| cpe:2.3:h:emerson:rx3i_cpe305:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:emerson:rx3i_cpe310_firmware:*:*:*:*:*:*:*:* | r9.90 (excluding) | |
| cpe:2.3:h:emerson:rx3i_cpe310:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:emerson:rx3i_cru320_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:emerson:rx3i_cru320:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:emerson:rx3i_cpe330_firmware:*:*:*:*:*:*:*:* | r9.90 (excluding) | |
| cpe:2.3:h:emerson:rx3i_cpe330:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:emerson:rx3i_cpe400_firmware:*:*:*:*:*:*:*:* | r9.90 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



