HIGH · 7.5

CVE-2021-27422

GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.

Vulnerability Description

GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
GeMultilin B30 Firmware< 8.10
GeMultilin B30-
GeMultilin B90 Firmware< 8.10
GeMultilin B90-
GeMultilin C60 Firmware< 8.10
GeMultilin C60-
GeMultilin C70 Firmware< 8.10
GeMultilin C70-
GeMultilin C95 Firmware< 8.10
GeMultilin C95-
GeMultilin D30 Firmware< 8.10
GeMultilin D30-
GeMultilin D60 Firmware< 8.10
GeMultilin D60-
GeMultilin F35 Firmware< 8.10
GeMultilin F35-
GeMultilin F60 Firmware< 8.10
GeMultilin F60-
GeMultilin G30 Firmware< 8.10
GeMultilin G30-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-27422?

CVE-2021-27422 is a vulnerability with a CVSS score of 7.5 (HIGH). GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.

How severe is CVE-2021-27422?

CVE-2021-27422 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-27422?

Check the references section above for vendor advisories and patch information. Affected products include: Ge Multilin B30 Firmware, Ge Multilin B30, Ge Multilin B90 Firmware, Ge Multilin B90, Ge Multilin C60 Firmware.