CVE-2021-27428
Published on: Not Yet Published
Last Modified on: 04/01/2022 03:28:00 PM UTC
Certain versions of Multilin B30 from Ge contain the following vulnerability:
GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of firmware file before uploading the UR IED. An illegitimate user could upgrade firmware without appropriate privileges. The weakness is assessed, and mitigation is implemented in firmware Version 8.10.
- CVE-2021-27428 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
- Affected Vendor/Software:
GE - UR family version < 8.1x
Vulnerability Patch/Work Around
- GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place. GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 7.5 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
GE UR family | CISA | www.cisa.gov text/html |
![]() |
Grid Passport Login : GE Grid Solutions | www.gegridsolutions.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Ge | Multilin B30 | - | All | All | All |
Operating System | Ge | Multilin B30 Firmware | All | All | All | All |
Hardware
| Ge | Multilin B90 | - | All | All | All |
Operating System | Ge | Multilin B90 Firmware | All | All | All | All |
Hardware
| Ge | Multilin C30 | - | All | All | All |
Operating System | Ge | Multilin C30 Firmware | All | All | All | All |
Hardware
| Ge | Multilin C60 | - | All | All | All |
Operating System | Ge | Multilin C60 Firmware | All | All | All | All |
Hardware
| Ge | Multilin C70 | - | All | All | All |
Operating System | Ge | Multilin C70 Firmware | All | All | All | All |
Hardware
| Ge | Multilin C95 | - | All | All | All |
Operating System | Ge | Multilin C95 Firmware | All | All | All | All |
Hardware
| Ge | Multilin D30 | - | All | All | All |
Operating System | Ge | Multilin D30 Firmware | All | All | All | All |
Hardware
| Ge | Multilin D60 | - | All | All | All |
Operating System | Ge | Multilin D60 Firmware | All | All | All | All |
Hardware
| Ge | Multilin F35 | - | All | All | All |
Operating System | Ge | Multilin F35 Firmware | All | All | All | All |
Hardware
| Ge | Multilin F60 | - | All | All | All |
Operating System | Ge | Multilin F60 Firmware | All | All | All | All |
Hardware
| Ge | Multilin G30 | - | All | All | All |
Operating System | Ge | Multilin G30 Firmware | All | All | All | All |
Hardware
| Ge | Multilin G60 | - | All | All | All |
Operating System | Ge | Multilin G60 Firmware | All | All | All | All |
Hardware
| Ge | Multilin L30 | - | All | All | All |
Operating System | Ge | Multilin L30 Firmware | All | All | All | All |
Hardware
| Ge | Multilin L60 | - | All | All | All |
Operating System | Ge | Multilin L60 Firmware | All | All | All | All |
Hardware
| Ge | Multilin L90 | - | All | All | All |
Operating System | Ge | Multilin L90 Firmware | All | All | All | All |
Hardware
| Ge | Multilin M60 | - | All | All | All |
Operating System | Ge | Multilin M60 Firmware | All | All | All | All |
Hardware
| Ge | Multilin N60 | - | All | All | All |
Operating System | Ge | Multilin N60 Firmware | All | All | All | All |
Hardware
| Ge | Multilin T35 | - | All | All | All |
Operating System | Ge | Multilin T35 Firmware | All | All | All | All |
Hardware
| Ge | Multilin T60 | - | All | All | All |
Operating System | Ge | Multilin T60 Firmware | All | All | All | All |
- cpe:2.3:h:ge:multilin_b30:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ge:multilin_b30_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:ge:multilin_b90:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ge:multilin_b90_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:ge:multilin_c30:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ge:multilin_c30_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:ge:multilin_c60:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ge:multilin_c60_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:ge:multilin_c70:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ge:multilin_c70_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:ge:multilin_c95:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ge:multilin_c95_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:ge:multilin_d30:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ge:multilin_d30_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:ge:multilin_d60:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ge:multilin_d60_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:ge:multilin_f35:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ge:multilin_f35_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:ge:multilin_f60:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ge:multilin_f60_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:ge:multilin_g30:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ge:multilin_g30_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:ge:multilin_g60:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ge:multilin_g60_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:ge:multilin_l30:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ge:multilin_l30_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:ge:multilin_l60:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ge:multilin_l60_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:ge:multilin_l90:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ge:multilin_l90_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:ge:multilin_m60:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ge:multilin_m60_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:ge:multilin_n60:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ge:multilin_n60_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:ge:multilin_t35:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ge:multilin_t35_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:ge:multilin_t60:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ge:multilin_t60_firmware:*:*:*:*:*:*:*:*:
Discovery Credit
SCADA-X, DOE’s Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program, Verve Industrial, and VuMetric reported these vulnerabilities to GE.
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-27428 : GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup confi… twitter.com/i/web/status/1… | 2022-03-23 20:20:48 |
![]() |
New vulnerability on the NVD: CVE-2021-27428 ift.tt/hfNexAm | 2022-03-23 22:33:20 |
![]() |
CVE-2021-27428 | 2022-03-23 21:39:10 |