Vulnerability Details CVE-2015-6456
                GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 have hardcoded credentials for a support account, which allows remote attackers to obtain administrative access, and consequently execute arbitrary code, by leveraging knowledge of the password.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.024
                        
                    
                    
                        
                            EPSS Ranking 84.4%
                        
                    
                 
                
                    CVSS Severity
                    
                    
                        
                            CVSS v2 Score 9.0
                        
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2015-6456
                        
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:ge:mds_pulsenet:3.0.0
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:ge:mds_pulsenet:3.0.1
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:ge:mds_pulsenet:3.1.3