CRITICAL · 9.8

CVE-2021-27428

GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of fir...

Vulnerability Description

GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of firmware file before uploading the UR IED. An illegitimate user could upgrade firmware without appropriate privileges. The weakness is assessed, and mitigation is implemented in firmware Version 8.10.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
GeMultilin B30 Firmware< 8.10
GeMultilin B30-
GeMultilin B90 Firmware< 8.10
GeMultilin B90-
GeMultilin C60 Firmware< 8.10
GeMultilin C60-
GeMultilin C70 Firmware< 8.10
GeMultilin C70-
GeMultilin C95 Firmware< 8.10
GeMultilin C95-
GeMultilin D30 Firmware< 8.10
GeMultilin D30-
GeMultilin D60 Firmware< 8.10
GeMultilin D60-
GeMultilin F35 Firmware< 8.10
GeMultilin F35-
GeMultilin F60 Firmware< 8.10
GeMultilin F60-
GeMultilin G30 Firmware< 8.10
GeMultilin G30-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-27428?

CVE-2021-27428 is a vulnerability with a CVSS score of 9.8 (CRITICAL). GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of fir...

How severe is CVE-2021-27428?

CVE-2021-27428 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-27428?

Check the references section above for vendor advisories and patch information. Affected products include: Ge Multilin B30 Firmware, Ge Multilin B30, Ge Multilin B90 Firmware, Ge Multilin B90, Ge Multilin C60 Firmware.