CVE-2018-10613
high · 7.5Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior.
7.5
CVSS
18.1%
EPSS (exploit prob.)
97th
EPSS percentile
2018-06-04
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-611
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| ge | mds_pulsenet | <= 3.2.1 |
| ge | mds_pulsenet | <= 3.2.1 |
Check a specific version with /api/v1/cve/match.
References
- http://www.gegridsolutions.com/app/DownloadFile.aspx?prod=pulsenet&type=9&file=1
- http://www.securityfocus.com/bid/104377
- https://ics-cert.us-cert.gov/advisories/ICSA-18-151-02
- http://www.gegridsolutions.com/app/DownloadFile.aspx?prod=pulsenet&type=9&file=1
- http://www.securityfocus.com/bid/104377
- https://ics-cert.us-cert.gov/advisories/ICSA-18-151-02
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-10613