CVE-2019-13559
CVE-2019-13559
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
07 Apr 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
GE Mark VIe Controller is shipped with pre-configured hard-coded credentials that may allow root-user access to the controller. A limited application of the affected product may ship without setup and configuration instructions immediately available to the end user. The bulk of controllers go into applications requiring the GE commissioning engineer to change default configurations during the installation process. GE recommends that users reset controller passwords during installation in the operating environment.
Affected products
n/a · GE Mark VIe ControllerWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →