CRITICAL · 9.8

CVE-2021-27426

GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user.

Vulnerability Description

GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
GeMultilin B30 Firmware< 8.10
GeMultilin B30-
GeMultilin B90 Firmware< 8.10
GeMultilin B90-
GeMultilin C60 Firmware< 8.10
GeMultilin C60-
GeMultilin C70 Firmware< 8.10
GeMultilin C70-
GeMultilin C95 Firmware< 8.10
GeMultilin C95-
GeMultilin D30 Firmware< 8.10
GeMultilin D30-
GeMultilin D60 Firmware< 8.10
GeMultilin D60-
GeMultilin F35 Firmware< 8.10
GeMultilin F35-
GeMultilin F60 Firmware< 8.10
GeMultilin F60-
GeMultilin G30 Firmware< 8.10
GeMultilin G30-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-27426?

CVE-2021-27426 is a vulnerability with a CVSS score of 9.8 (CRITICAL). GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user.

How severe is CVE-2021-27426?

CVE-2021-27426 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-27426?

Check the references section above for vendor advisories and patch information. Affected products include: Ge Multilin B30 Firmware, Ge Multilin B30, Ge Multilin B90 Firmware, Ge Multilin B90, Ge Multilin C60 Firmware.