ID

VAR-201911-1784


TITLE

GE PLC IC695CPE330 has authentication bypass vulnerability

Trust: 0.6

sources: CNVD: CNVD-2019-39417

DESCRIPTION

GE PLC IC695CPE330 is a programmable logic controller from General Electric. GE PLC IC695CPE330 has an authentication bypass vulnerability. Attackers can use this vulnerability to bypass permission verification and obtain all web content

Trust: 0.72

sources: CNVD: CNVD-2019-39417 // IVD: 19906019-dc40-4c4d-8585-cf4eaac17218

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 19906019-dc40-4c4d-8585-cf4eaac17218 // CNVD: CNVD-2019-39417

AFFECTED PRODUCTS

vendor:general electricmodel:plc ic695cpe330scope:eqversion:4.0

Trust: 0.8

sources: IVD: 19906019-dc40-4c4d-8585-cf4eaac17218 // CNVD: CNVD-2019-39417

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2019-39417
value: MEDIUM

Trust: 0.6

IVD: 19906019-dc40-4c4d-8585-cf4eaac17218
value: MEDIUM

Trust: 0.2

CNVD: CNVD-2019-39417
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 19906019-dc40-4c4d-8585-cf4eaac17218
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: 19906019-dc40-4c4d-8585-cf4eaac17218 // CNVD: CNVD-2019-39417

TYPE

Access verification error

Trust: 0.2

sources: IVD: 19906019-dc40-4c4d-8585-cf4eaac17218

EXTERNAL IDS

db:CNVDid:CNVD-2019-39417

Trust: 0.8

db:IVDid:19906019-DC40-4C4D-8585-CF4EAAC17218

Trust: 0.2

sources: IVD: 19906019-dc40-4c4d-8585-cf4eaac17218 // CNVD: CNVD-2019-39417

SOURCES

db:IVDid:19906019-dc40-4c4d-8585-cf4eaac17218
db:CNVDid:CNVD-2019-39417

LAST UPDATE DATE

2022-05-17T01:52:30.609000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-39417date:2019-11-07T00:00:00

SOURCES RELEASE DATE

db:IVDid:19906019-dc40-4c4d-8585-cf4eaac17218date:2019-11-06T00:00:00
db:CNVDid:CNVD-2019-39417date:2019-11-09T00:00:00