A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06 that could allow an authenticated remote attacker to execute arbitrary code on the system.
Solution:
Workaround:
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-21-005-03 | us government resource third party advisory mitigation |
https://www.gegridsolutions.com/app/DownloadFile.aspx?prod=RT430&type=21&file=5 | permissions required |