CVE-2021-27418
- EPSS 0.22%
- Published 23.03.2022 20:15:08
- Last modified 21.11.2024 05:57:56
GE UR firmware versions prior to version 8.1x supports web interface with read-only access. The device fails to properly validate user input, making it possible to perform cross-site scripting attacks, which may be used to send a malicious script. Al...
CVE-2021-27420
- EPSS 0.22%
- Published 23.03.2022 20:15:08
- Last modified 21.11.2024 05:57:57
GE UR firmware versions prior to version 8.1x web server task does not properly handle receipt of unsupported HTTP verbs, resulting in the web server becoming temporarily unresponsive after receiving a series of unsupported HTTP requests. When unresp...
CVE-2021-27422
- EPSS 0.1%
- Published 23.03.2022 20:15:08
- Last modified 21.11.2024 05:57:57
GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.
CVE-2021-27424
- EPSS 0.19%
- Published 23.03.2022 20:15:08
- Last modified 21.11.2024 05:57:57
GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a “Last-key pressed” MODBUS register can be used to gain unauthorized information.
CVE-2021-27426
- EPSS 0.25%
- Published 23.03.2022 20:15:08
- Last modified 21.11.2024 05:57:57
GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user.
CVE-2021-27428
- EPSS 0.25%
- Published 23.03.2022 20:15:08
- Last modified 21.11.2024 05:57:58
GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of firmware file before uploading the UR IED. An illegit...