GE Reason RT43X Clocks Code Injection
Vulnerability Description
A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06 that could allow an authenticated remote attacker to execute arbitrary code on the system.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-25197
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Tom Westenberg of Thales UK reported these vulnerabilities to GE.