GE Communicator
GE Communicator versions 3.15 and earlier include a vulnerable version of third-party library Gigasoft (v5 and prior) that contains a buffer overflow or memory corruption vulnerability (CWE-122). Exploitation could allow an attacker to execute arbitrary code on the Communicator host or cause a denial-of-service condition by crashing the application. The vulnerability is remotely exploitable and requires no authentication, though user interaction (such as opening a file or clicking a link) may be involved depending on the specific attack vector. No known public exploits currently target this vulnerability.
- Network access to the Communicator application (port and protocol depend on deployment)
- User interaction may be required (user must open a crafted file or visit a malicious URL, depending on attack vector)
- Communicator version 3.15 or earlier running embedded Gigasoft v5 or prior
Patching may require device reboot — plan for process interruption
/api/v1/advisories/a2958c99-1d55-4a9f-ae46-d0df6115330eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.