Vulnerabilities (CVE)

Filtered by vendor Ge Subscribe
Filtered by product Mds Pulsenet
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-6459 1 Ge 1 Mds Pulsenet 2015-09-23 10.0 HIGH N/A
Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 allows remote attackers to read or delete arbitrary files via a full pathname.
CVE-2015-6456 1 Ge 1 Mds Pulsenet 2015-09-23 9.0 HIGH N/A
GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 have hardcoded credentials for a support account, which allows remote attackers to obtain administrative access, and consequently execute arbitrary code, by leveraging knowledge of the password.