5.3
CVE-2021-27424
- EPSS 0.18%
- Veröffentlicht 23.03.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 05:57:57
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
GE UR family exposure of sensitive information to an unauthorized actor
GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a “Last-key pressed” MODBUS register can be used to gain unauthorized information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ge ≫ Multilin B30 Firmware Version < 8.10
Ge ≫ Multilin B90 Firmware Version < 8.10
Ge ≫ Multilin C60 Firmware Version < 8.10
Ge ≫ Multilin C70 Firmware Version < 8.10
Ge ≫ Multilin C95 Firmware Version < 8.10
Ge ≫ Multilin D30 Firmware Version < 8.10
Ge ≫ Multilin D60 Firmware Version < 8.10
Ge ≫ Multilin F35 Firmware Version < 8.10
Ge ≫ Multilin F60 Firmware Version < 8.10
Ge ≫ Multilin G30 Firmware Version < 8.10
Ge ≫ Multilin G60 Firmware Version < 8.10
Ge ≫ Multilin L30 Firmware Version < 8.10
Ge ≫ Multilin L60 Firmware Version < 8.10
Ge ≫ Multilin L90 Firmware Version < 8.10
Ge ≫ Multilin M60 Firmware Version < 8.10
Ge ≫ Multilin N60 Firmware Version < 8.10
Ge ≫ Multilin T35 Firmware Version < 8.10
Ge ≫ Multilin T60 Firmware Version < 8.10
Ge ≫ Multilin C30 Firmware Version < 8.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.388 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
| ics-cert@hq.dhs.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-668 Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.