Vulnerability Description
GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ge | Multilin B30 Firmware | < 8.10 |
| Ge | Multilin B30 | - |
| Ge | Multilin B90 Firmware | < 8.10 |
| Ge | Multilin B90 | - |
| Ge | Multilin C60 Firmware | < 8.10 |
| Ge | Multilin C60 | - |
| Ge | Multilin C70 Firmware | < 8.10 |
| Ge | Multilin C70 | - |
| Ge | Multilin C95 Firmware | < 8.10 |
| Ge | Multilin C95 | - |
| Ge | Multilin D30 Firmware | < 8.10 |
| Ge | Multilin D30 | - |
| Ge | Multilin D60 Firmware | < 8.10 |
| Ge | Multilin D60 | - |
| Ge | Multilin F35 Firmware | < 8.10 |
| Ge | Multilin F35 | - |
| Ge | Multilin F60 Firmware | < 8.10 |
| Ge | Multilin F60 | - |
| Ge | Multilin G30 Firmware | < 8.10 |
| Ge | Multilin G30 | - |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-075-02MitigationThird Party AdvisoryUS Government Resource
- https://www.gegridsolutions.com/Passport/Login.aspxPermissions RequiredVendor Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-075-02MitigationThird Party AdvisoryUS Government Resource
- https://www.gegridsolutions.com/Passport/Login.aspxPermissions RequiredVendor Advisory
FAQ
What is CVE-2021-27426?
CVE-2021-27426 is a vulnerability with a CVSS score of 9.8 (CRITICAL). GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user.
How severe is CVE-2021-27426?
CVE-2021-27426 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-27426?
Check the references section above for vendor advisories and patch information. Affected products include: Ge Multilin B30 Firmware, Ge Multilin B30, Ge Multilin B90 Firmware, Ge Multilin B90, Ge Multilin C60 Firmware.