SNMP/Web Interface Command Injection and Information Disclosure Vulnerabilities
9 May. 2016
Summary
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to execute arbitrary commands.
Vulnerable Systems:
*General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8
Immune Systems:
*General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware after 4.8
SNMP/Web Interface is prone to a command-injection vulnerability and an information-disclosure vulnerability. Exploiting these issues could allow an attacker to gain access to potentially sensitive information and execute arbitrary commands in the context of the affected device.