CVE-2018-8867

UnknownEPSS 3.47%

Last modified

CVE-2018-8867 is a vulnerability of currently unknown severity. In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 and prior, PACSystems RSTi-EP CPE 100 all versions, and PACSystems CPU320/CRU320 RXi all versions, the device does not properly validate input, which could allow a remote attacker to send specially crafted packets causing the device to become unavailable.. EPSS estimates a 3.47% chance of exploitation in the next 30 days.

Description

In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 and prior, PACSystems RSTi-EP CPE 100 all versions, and PACSystems CPU320/CRU320 RXi all versions, the device does not properly validate input, which could allow a remote attacker to send specially crafted packets causing the device to become unavailable.

Metrics

EPSS Probability
3.47%

87.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
GePacsystems Rx3i Cpe305 Firmware<= 9.20
GePacsystems Rx3i Cpe310 Firmware<= 9.20
GeRx3i Cpe330 Firmware<= 9.21
GeRx3i Cpe 400 Firmware<= 9.30
GePacsystems Rsti-Ep Cpe 100 FirmwareAll versions
GePacsystems Cpu320 FirmwareAll versions
GePacsystems Cru320 FirmwareAll versions
GePacsystems Rxi FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-8867?
In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 and prior, PACSystems RSTi-EP CPE 100 all versions, and PACSystems CPU320/CRU320 RXi all versions, the device does not properly validate input, which could allow a remote attacker to send specially crafted packets causing the device to become unavailable.
How severe is CVE-2018-8867?
Severity scoring for CVE-2018-8867 is pending analysis. The EPSS model estimates a 3.47% probability of exploitation in the next 30 days.
How do I fix CVE-2018-8867?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-8867?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST