QID 591310
Date Published: 2023-02-03
QID 591310: General Electric C90Plus, D90Plus Missing Authentication Vulnerability (upsb1601)
AFFECTED PRODUCTS
GE C90Plus Automation Control System and the D90Plus Line Distance Protection system: Firmware version 1.84
GE recommends upgrading to firmware version 1.85 to resolve this issue.
QID Detection Logic:
This QID checks for the Vulnerable version of General Electric C90Plus and/or D90Plus using passive scanning
A vulnerability has been identified in the GE C90Plus Automation Control System and the D90Plus Line Distance Protection system that could result in unauthorized access to relay settings. Firmware version 1.84 fails to prompt for authentication prior to reconfiguration when login services are enabled, which could result in unauthorized read and write access to settings. This vulnerability is accessible through connecting directly via USB or remotely via the IP based network and only affects firmware version 1.84.
Customers are advised to refer to CERT MITIGATIONS section upsb1601 for affected packages and patching details.
CVEs related to QID 591310
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| upsb1601 |
|