CVE-2019-6546

HIGH

GE Communicator < 4.0.517 - Uncontrolled Search Path

Title source: rule

Description

GE Communicator, all versions prior to 4.0.517, allows an attacker to place malicious files within the working directory of the program, which may allow an attacker to manipulate widgets and UI elements.

Scores

CVSS v3 7.8
EPSS 0.0015
EPSS Percentile 36.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (1)

ge/ge_communicator < 4.0.517

Timeline

Published May 09, 2019
Tracked Since Feb 18, 2026