Vulnerability Description
GE UR firmware versions prior to version 8.1x supports web interface with read-only access. The device fails to properly validate user input, making it possible to perform cross-site scripting attacks, which may be used to send a malicious script. Also, UR Firmware web server does not perform HTML encoding of user-supplied strings.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ge | Multilin B30 Firmware | < 8.10 |
| Ge | Multilin B30 | - |
| Ge | Multilin B90 Firmware | < 8.10 |
| Ge | Multilin B90 | - |
| Ge | Multilin C60 Firmware | < 8.10 |
| Ge | Multilin C60 | - |
| Ge | Multilin C70 Firmware | < 8.10 |
| Ge | Multilin C70 | - |
| Ge | Multilin C95 Firmware | < 8.10 |
| Ge | Multilin C95 | - |
| Ge | Multilin D30 Firmware | < 8.10 |
| Ge | Multilin D30 | - |
| Ge | Multilin D60 Firmware | < 8.10 |
| Ge | Multilin D60 | - |
| Ge | Multilin F35 Firmware | < 8.10 |
| Ge | Multilin F35 | - |
| Ge | Multilin F60 Firmware | < 8.10 |
| Ge | Multilin F60 | - |
| Ge | Multilin G30 Firmware | < 8.10 |
| Ge | Multilin G30 | - |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-075-02MitigationThird Party AdvisoryUS Government Resource
- https://www.gegridsolutions.com/Passport/Login.aspxPermissions RequiredVendor Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-075-02MitigationThird Party AdvisoryUS Government Resource
- https://www.gegridsolutions.com/Passport/Login.aspxPermissions RequiredVendor Advisory
FAQ
What is CVE-2021-27418?
CVE-2021-27418 is a vulnerability with a CVSS score of 5.3 (MEDIUM). GE UR firmware versions prior to version 8.1x supports web interface with read-only access. The device fails to properly validate user input, making it possible to perform cross-site scripting attacks...
How severe is CVE-2021-27418?
CVE-2021-27418 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27418?
Check the references section above for vendor advisories and patch information. Affected products include: Ge Multilin B30 Firmware, Ge Multilin B30, Ge Multilin B90 Firmware, Ge Multilin B90, Ge Multilin C60 Firmware.