DHS: Hard-Coded Password Found in GE Industrial Networking Gear
ID: 8736fc6b-f050-58ab-9cb9-bd55d24b2ead
STIX ID: report--8736fc6b-f050-58ab-9cb9-bd55d24b2ead
Feed Name: Security Ledger
Threat Score
ICS-CERT and DHS warn that many GE MultiLink industrial Ethernet switches contain a hard-coded administrative account (CVE-2016-2310b) that could allow remote unauthorized administrative access. GE released firmware updates to remove the default account for specific MultiLink models; organizations are advised to evaluate impact and apply the updates. The advisory notes no confirmed exploitation but emphasizes the high relevance for critical infrastructure deployments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
