HTTP: GE MDS PulseNET Spring Remoting HTTPInvoker Insecure Deserialization

This signature detects attempts to exploit insecure deserialization vulnerability against GE MDS PulseNET and PulseNET Enterprise. Successful exploitation can result in arbitrary code execution in the context of the user running PulseNET.

Extended Description

Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to allow unauthenticated users to launch applications and support remote code execution through web services.

Affected Products

Ge mds_pulsenet

Short Name
HTTP:INSEC-DSERILZN-1
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2018-10611 Deserialization GE HTTPInvoker Insecure MDS PulseNET Remoting Spring
Release Date
07/23/2018
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Ge

CVSS Score

7.5

Found a potential security threat?