The software contains a hard-coded password that could allow an attacker to take control of the merging unit using these hard-coded credentials on the MU320E (all firmware versions prior to v04A00.1).
📦
mu320e
Vendor: ge
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
0
Remote Access
Total CVEs
3
Total Indexed
Avg. EPSS
0.23%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
7.8
CVSS
Severity: HIGH
7.8
CVSS
SSH server configuration file does not implement some best practices. This could lead to a weakening of the SSH protocol strength, which could lead to additional misconfiguration or be leveraged as part of a larger attack on the MU320E (all firmware versions prior to v04A00.1).
Severity: HIGH
7.8
CVSS
A miscommunication in the file system allows adversaries with access to the MU320E to escalate privileges on the MU320E (all firmware versions prior to v04A00.1).
Severity: HIGH