V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2021-27426
CVE
Critical

GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which i…

CVSS
9.8
Critical
EPSS
0.00
p52
Published
2021-01-01
Updated
2021-01-01
Description

GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user.

Tags · CWE
Pre-auth
CWE-453
Affected products
Multilin_b30_firmwareMultilin_b90_firmwareMultilin_c30_firmwareMultilin_c60_firmwareMultilin_c70_firmwareMultilin_c95_firmwareMultilin_d30_firmwareMultilin_d60_firmwareMultilin_f35_firmwareMultilin_f60_firmwareMultilin_g30_firmwareMultilin_g60_firmwareMultilin_l30_firmwareMultilin_l60_firmwareMultilin_l90_firmwareMultilin_m60_firmwareMultilin_n60_firmwareMultilin_t35_firmwareMultilin_t60_firmware
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2021-01-01
Published
2021-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.003 · p52
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
multilin_b30_firmware*Tracked
multilin_b90_firmware*Tracked
multilin_c30_firmware*Tracked
multilin_c60_firmware*Tracked
multilin_c70_firmware*Tracked
multilin_c95_firmware*Tracked
multilin_d30_firmware*Tracked
multilin_d60_firmware*Tracked
multilin_f35_firmware*Tracked
multilin_f60_firmware*Tracked
multilin_g30_firmware*Tracked
multilin_g60_firmware*Tracked
multilin_l30_firmware*Tracked
multilin_l60_firmware*Tracked
multilin_l90_firmware*Tracked
multilin_m60_firmware*Tracked
multilin_n60_firmware*Tracked
multilin_t35_firmware*Tracked
multilin_t60_firmware*Tracked
Source databases
CVE