CVE-2018-8867 is a denial-of-service vulnerability affecting various GE PACSystems and RSTi-EP CPE devices, including specific versions of RX3i CPE305/310, RX3i CPE330, RX3i CPE400, and all versions of PACSystems RSTi-EP CPE 100 and PACSystems CPU320/CRU320 RXi. This flaw stems from improper input validation, allowing a remote attacker to send specially crafted packets to render the device unavailable. Rated 7.5 HIGH on the CVSS scale, it presents a high availability impact with low attack complexity and no user interaction required. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.20CPE matchmatch criteria | cpe:2.3:o:ge:pacsystems_rx3i_cpe305_firmware:*:*:*:*:*:*:*:* | ||
<= 9.20CPE matchmatch criteria | cpe:2.3:o:ge:pacsystems_rx3i_cpe310_firmware:*:*:*:*:*:*:*:* | ||
<= 9.21CPE matchmatch criteria | cpe:2.3:o:ge:rx3i_cpe330_firmware:*:*:*:*:*:*:*:* | ||
<= 9.30CPE matchmatch criteria | cpe:2.3:o:ge:rx3i_cpe_400_firmware:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:ge:pacsystems_rsti-ep_cpe_100_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.