CVE-2018-19003
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
14/12/2018
Last modified:
09/10/2019
Description
GE Mark VIe, EX2100e, EX2100e_Reg, and LS2100e Versions 03.03.28C to 05.02.04C, EX2100e All versions prior to v04.09.00C, EX2100e_Reg All versions prior to v04.09.00C, and LS2100e All versions prior to v04.09.00C The affected versions of the application have a path traversal vulnerability that fails to restrict the ability of an attacker to gain access to restricted information.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:ge:ex2100e_firmware:*:*:*:*:*:*:*:* | 04.09.00c (excluding) | |
| cpe:2.3:o:ge:ex2100e:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ge:ls2100e_firmware:*:*:*:*:*:*:*:* | 04.09.00c (excluding) | |
| cpe:2.3:h:ge:ls2100e:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ge:ex2100e_firmware:*:*:*:*:*:*:*:* | 03.03.28c (including) | 05.02.04c (including) |
| cpe:2.3:h:ge:ex2100e:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ge:ls2100e_firmware:*:*:*:*:*:*:*:* | 03.03.28c (including) | 05.02.04c (including) |
| cpe:2.3:h:ge:ls2100e:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ge:mark_vle_firmware:*:*:*:*:*:*:*:* | 03.03.28c (including) | 05.02.04c (including) |
| cpe:2.3:h:ge:mark_vle:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



