Vulnerability Description
GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a “Last-key pressed” MODBUS register can be used to gain unauthorized information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ge | Multilin B30 Firmware | < 8.10 |
| Ge | Multilin B30 | - |
| Ge | Multilin B90 Firmware | < 8.10 |
| Ge | Multilin B90 | - |
| Ge | Multilin C60 Firmware | < 8.10 |
| Ge | Multilin C60 | - |
| Ge | Multilin C70 Firmware | < 8.10 |
| Ge | Multilin C70 | - |
| Ge | Multilin C95 Firmware | < 8.10 |
| Ge | Multilin C95 | - |
| Ge | Multilin D30 Firmware | < 8.10 |
| Ge | Multilin D30 | - |
| Ge | Multilin D60 Firmware | < 8.10 |
| Ge | Multilin D60 | - |
| Ge | Multilin F35 Firmware | < 8.10 |
| Ge | Multilin F35 | - |
| Ge | Multilin F60 Firmware | < 8.10 |
| Ge | Multilin F60 | - |
| Ge | Multilin G30 Firmware | < 8.10 |
| Ge | Multilin G30 | - |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-075-02MitigationThird Party AdvisoryUS Government Resource
- https://www.gegridsolutions.com/Passport/Login.aspxPermissions RequiredVendor Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-075-02MitigationThird Party AdvisoryUS Government Resource
- https://www.gegridsolutions.com/Passport/Login.aspxPermissions RequiredVendor Advisory
FAQ
What is CVE-2021-27424?
CVE-2021-27424 is a vulnerability with a CVSS score of 5.3 (MEDIUM). GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a “Last-key pressed” MODBUS register can be used to gain unauthorized info...
How severe is CVE-2021-27424?
CVE-2021-27424 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27424?
Check the references section above for vendor advisories and patch information. Affected products include: Ge Multilin B30 Firmware, Ge Multilin B30, Ge Multilin B90 Firmware, Ge Multilin B90, Ge Multilin C60 Firmware.