CVE-2019-6548

CRITICAL

GE Communicator < 4.0.517 - Use of Hard-coded Credentials

Title source: llm
STIX 2.1

Description

GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may allow control over the database. This service is inaccessible to attackers if Windows default firewall settings are used by the end user.

References (1)

Core 1
Core References
Mitigation, Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-19-122-02

Scores

CVSS v3 9.8
EPSS 0.0128
EPSS Percentile 66.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (1)
ge/ge_communicator < 4.0.517
Published May 09, 2019
Tracked Since Feb 18, 2026