CVE-2018-19003

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
14/12/2018
Last modified:
09/10/2019

Description

GE Mark VIe, EX2100e, EX2100e_Reg, and LS2100e Versions 03.03.28C to 05.02.04C, EX2100e All versions prior to v04.09.00C, EX2100e_Reg All versions prior to v04.09.00C, and LS2100e All versions prior to v04.09.00C The affected versions of the application have a path traversal vulnerability that fails to restrict the ability of an attacker to gain access to restricted information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ge:ex2100e_firmware:*:*:*:*:*:*:*:* 04.09.00c (excluding)
cpe:2.3:o:ge:ex2100e:-:*:*:*:*:*:*:*
cpe:2.3:o:ge:ls2100e_firmware:*:*:*:*:*:*:*:* 04.09.00c (excluding)
cpe:2.3:h:ge:ls2100e:-:*:*:*:*:*:*:*
cpe:2.3:o:ge:ex2100e_firmware:*:*:*:*:*:*:*:* 03.03.28c (including) 05.02.04c (including)
cpe:2.3:h:ge:ex2100e:-:*:*:*:*:*:*:*
cpe:2.3:o:ge:ls2100e_firmware:*:*:*:*:*:*:*:* 03.03.28c (including) 05.02.04c (including)
cpe:2.3:h:ge:ls2100e:-:*:*:*:*:*:*:*
cpe:2.3:o:ge:mark_vle_firmware:*:*:*:*:*:*:*:* 03.03.28c (including) 05.02.04c (including)
cpe:2.3:h:ge:mark_vle:-:*:*:*:*:*:*:*