CVE-2019-6544 Information
Feb 14, 2021
cve
Description
GE Communicator all versions prior to 4.0.517 has a service running with system privileges that may allow an unprivileged user to perform certain administrative actions which may allow the execution of scheduled scripts with system administrator privileges. This service is inaccessible to attackers if Windows default firewall settings are used by the end user.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Reference
https://ics-cert.us-cert.gov/advisories/ICSA-19-122-02
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
LOW
Base Severity
5.6
Share on: