CVE-2019-13524

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
16/01/2020
Last modified:
27/01/2020

Description

GE PACSystems RX3i CPE100/115: All versions prior to R9.85,CPE302/305/310/330/400/410: All versions prior to R9.90,CRU/320 All versions(End of Life) may allow an attacker sending specially manipulated packets to cause the module state to change to halt-mode, resulting in a denial-of-service condition. An operator must reboot the CPU module after removing battery or energy pack to recover from halt-mode.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:emerson:rx3i_cpe100_firmware:*:*:*:*:*:*:*:* r9.85 (excluding)
cpe:2.3:h:emerson:rx3i_cpe100:-:*:*:*:*:*:*:*
cpe:2.3:o:emerson:rx3i_cpe115_firmware:*:*:*:*:*:*:*:* r9.85 (excluding)
cpe:2.3:h:emerson:rx3i_cpe115:-:*:*:*:*:*:*:*
cpe:2.3:o:emerson:rx3i_cpe302_firmware:*:*:*:*:*:*:*:* r9.90 (excluding)
cpe:2.3:h:emerson:rx3i_cpe302:-:*:*:*:*:*:*:*
cpe:2.3:o:emerson:rx3i_cpe305_firmware:*:*:*:*:*:*:*:* r9.90 (excluding)
cpe:2.3:h:emerson:rx3i_cpe305:-:*:*:*:*:*:*:*
cpe:2.3:o:emerson:rx3i_cpe310_firmware:*:*:*:*:*:*:*:* r9.90 (excluding)
cpe:2.3:h:emerson:rx3i_cpe310:-:*:*:*:*:*:*:*
cpe:2.3:o:emerson:rx3i_cru320_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:emerson:rx3i_cru320:-:*:*:*:*:*:*:*
cpe:2.3:o:emerson:rx3i_cpe330_firmware:*:*:*:*:*:*:*:* r9.90 (excluding)
cpe:2.3:h:emerson:rx3i_cpe330:-:*:*:*:*:*:*:*
cpe:2.3:o:emerson:rx3i_cpe400_firmware:*:*:*:*:*:*:*:* r9.90 (excluding)


References to Advisories, Solutions, and Tools