General Electric Update
3645Warning Date
Severity Level
Warning Number
Target Sector
20 January, 2020
● High
2020-819
Communication and information technology - Energy - Transportation - Water and Utilities - Defence - HealthCare - Manufacturing - Commercial Facilities - Government Facilities
Description:
General Electric has released security update to address a vulnerability in the following product:
- CPE100: All versions prior to R9.85
- CPE115: All versions prior to R9.85
- CPE302: All versions prior to R9.90
- CPE305: All versions prior to R9.90
- CPE310: All versions prior to R9.90
- CPE330: All versions prior to R9.90
- CPE400: All versions prior to R9.90
- CPL410: All versions prior to R9.90
Threats:
The vulnerability cause the module state to change to halt-mode, resulting in a denial-of-service condition.
Best practice and Recommendations:
The CERT team encourages users to update the affects products:
- Version R9.85
- Version R9.90
- CPE302 – Upgrade Kit: CPE302_FW9_90_41G2552-FW01-000-A3.zip
- CPE305 – Upgrade Kit: CPE305_FW9_90_41G1733-MS10-000-A20.zip
- CPE310 – Upgrade Kit: CPE310_FW9_90_41G1734-MS10-000-A20.zip
- CPE330 – Upgrade Kit: CPE330_FW9_90_41G2016-FW01-000-A16.zip
- CPE400 – Upgrade Kit: CPE400_FW9_90_41G2376-FW01-000-A7.zip
- CPL410 – Upgrade Kit: CPL410_FW9_90_41G2617-FW01-000-A3.zip