CVE-2018-8867

In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 and prior, PACSystems RSTi-EP CPE 100 all versions, and PACSystems CPU320/CRU320 RXi all versions, the device does not properly validate input, which could allow a remote attacker to send specially crafted packets causing the device to become unavailable.
References
Link Resource
http://www.securityfocus.com/bid/104241 Third Party Advisory VDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-18-137-01 Mitigation Third Party Advisory US Government Resource
http://www.securityfocus.com/bid/104241 Third Party Advisory VDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-18-137-01 Mitigation Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ge:pacsystems_rx3i_cpe305_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ge:pacsystems_rx3i_cpe305:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ge:pacsystems_rx3i_cpe310_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ge:pacsystems_rx3i_cpe310:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:ge:rx3i_cpe330_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ge:rx3i_cpe330:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:ge:rx3i_cpe_400_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ge:rx3i_cpe_400:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:ge:pacsystems_rsti-ep_cpe_100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:pacsystems_rsti-ep_cpe_100:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:ge:pacsystems_cpu320_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:pacsystems_cpu320:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:ge:pacsystems_cru320_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:pacsystems_cru320:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:ge:pacsystems_rxi_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:pacsystems_rxi:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:14

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/104241 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/104241 - Third Party Advisory, VDB Entry
References () https://ics-cert.us-cert.gov/advisories/ICSA-18-137-01 - Mitigation, Third Party Advisory, US Government Resource () https://ics-cert.us-cert.gov/advisories/ICSA-18-137-01 - Mitigation, Third Party Advisory, US Government Resource

Information

Published : 2018-05-18 20:29

Updated : 2024-11-21 04:14


NVD link : CVE-2018-8867

Mitre link : CVE-2018-8867

CVE.ORG link : CVE-2018-8867


JSON object : View

Products Affected

ge

  • pacsystems_rx3i_cpe310_firmware
  • pacsystems_rxi
  • rx3i_cpe_400_firmware
  • rx3i_cpe330
  • pacsystems_rsti-ep_cpe_100
  • rx3i_cpe_400
  • pacsystems_cru320
  • pacsystems_rxi_firmware
  • pacsystems_rsti-ep_cpe_100_firmware
  • pacsystems_cpu320
  • pacsystems_rx3i_cpe305_firmware
  • pacsystems_cpu320_firmware
  • pacsystems_cru320_firmware
  • pacsystems_rx3i_cpe305
  • pacsystems_rx3i_cpe310
  • rx3i_cpe330_firmware
CWE
CWE-20

Improper Input Validation