Vulnerability Description
In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 and prior, PACSystems RSTi-EP CPE 100 all versions, and PACSystems CPU320/CRU320 RXi all versions, the device does not properly validate input, which could allow a remote attacker to send specially crafted packets causing the device to become unavailable.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ge | Pacsystems Rx3I Cpe305 Firmware | <= 9.20 |
| Ge | Pacsystems Rx3I Cpe305 | - |
| Ge | Pacsystems Rx3I Cpe310 Firmware | <= 9.20 |
| Ge | Pacsystems Rx3I Cpe310 | - |
| Ge | Rx3I Cpe330 Firmware | <= 9.21 |
| Ge | Rx3I Cpe330 | - |
| Ge | Rx3I Cpe 400 Firmware | <= 9.30 |
| Ge | Rx3I Cpe 400 | - |
| Ge | Pacsystems Rsti-Ep Cpe 100 Firmware | - |
| Ge | Pacsystems Rsti-Ep Cpe 100 | - |
| Ge | Pacsystems Cpu320 Firmware | - |
| Ge | Pacsystems Cpu320 | - |
| Ge | Pacsystems Cru320 Firmware | - |
| Ge | Pacsystems Cru320 | - |
| Ge | Pacsystems Rxi Firmware | - |
| Ge | Pacsystems Rxi | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/104241Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-137-01MitigationThird Party AdvisoryUS Government Resource
- http://www.securityfocus.com/bid/104241Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-137-01MitigationThird Party AdvisoryUS Government Resource
FAQ
What is CVE-2018-8867?
CVE-2018-8867 is a vulnerability with a CVSS score of 7.5 (HIGH). In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 and prior, PACSystems RSTi-EP CPE 100 all versions, and PACSystems CPU320/CRU320 ...
How severe is CVE-2018-8867?
CVE-2018-8867 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-8867?
Check the references section above for vendor advisories and patch information. Affected products include: Ge Pacsystems Rx3I Cpe305 Firmware, Ge Pacsystems Rx3I Cpe305, Ge Pacsystems Rx3I Cpe310 Firmware, Ge Pacsystems Rx3I Cpe310, Ge Rx3I Cpe330 Firmware.