APP: GE MDS PulseNET Remote Invocation Insecure Deserialization

This signature detects attempts to exploit a known vulnerability in GE MDS PulseNET and PulseNET Enterprise. Successful exploitation can result in arbitrary code execution in the context of the user running PulseNET.

Extended Description

Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to allow unauthenticated users to launch applications and support remote code execution through web services.

Affected Products

Ge mds_pulsenet

References

BugTraq: 104377

CVE: CVE-2018-10611

Short Name
APP:MISC:GE-MDS-PULSENET-ID
Severity
Major
Recommended
True
Recommended Action
Drop
Category
APP
Keywords
CVE-2018-10611 Deserialization GE Insecure Invocation MDS PulseNET Remote bid:104377
Release Date
06/14/2018
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
Port
TCP/4445,4448
False Positive
Unknown
Vendors

Ge

CVSS Score

7.5

Found a potential security threat?