Vulnerability Description
GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of firmware file before uploading the UR IED. An illegitimate user could upgrade firmware without appropriate privileges. The weakness is assessed, and mitigation is implemented in firmware Version 8.10.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ge | Multilin B30 Firmware | < 8.10 |
| Ge | Multilin B30 | - |
| Ge | Multilin B90 Firmware | < 8.10 |
| Ge | Multilin B90 | - |
| Ge | Multilin C60 Firmware | < 8.10 |
| Ge | Multilin C60 | - |
| Ge | Multilin C70 Firmware | < 8.10 |
| Ge | Multilin C70 | - |
| Ge | Multilin C95 Firmware | < 8.10 |
| Ge | Multilin C95 | - |
| Ge | Multilin D30 Firmware | < 8.10 |
| Ge | Multilin D30 | - |
| Ge | Multilin D60 Firmware | < 8.10 |
| Ge | Multilin D60 | - |
| Ge | Multilin F35 Firmware | < 8.10 |
| Ge | Multilin F35 | - |
| Ge | Multilin F60 Firmware | < 8.10 |
| Ge | Multilin F60 | - |
| Ge | Multilin G30 Firmware | < 8.10 |
| Ge | Multilin G30 | - |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-075-02MitigationThird Party AdvisoryUS Government Resource
- https://www.gegridsolutions.com/Passport/Login.aspxPermissions RequiredVendor Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-075-02MitigationThird Party AdvisoryUS Government Resource
- https://www.gegridsolutions.com/Passport/Login.aspxPermissions RequiredVendor Advisory
FAQ
What is CVE-2021-27428?
CVE-2021-27428 is a vulnerability with a CVSS score of 9.8 (CRITICAL). GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of fir...
How severe is CVE-2021-27428?
CVE-2021-27428 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-27428?
Check the references section above for vendor advisories and patch information. Affected products include: Ge Multilin B30 Firmware, Ge Multilin B30, Ge Multilin B90 Firmware, Ge Multilin B90, Ge Multilin C60 Firmware.