CVE-2015-6459

critical
Published 2015-09-18 · Modified 2026-05-06
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 allows remote attackers to read or delete arbitrary files via a full pathname.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: ics-cert@hq.dhs.gov — http://www.gedigitalenergy.com/app/resources.aspx?prod=pulsenet&type=9

Application impact

VendorProductVersionsFixed
gemds_pulsenet{"endIncluding":"3.1.3"}

References

CWEs

CWE-22

Verify integrity in audit chain (admin only). AS-IS.