Description
GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.
Published: 2022-03-23
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10, or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 (login required).


Vendor Workaround

GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place. GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-14176 GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.
History

Wed, 16 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Ge Multilin B30 Multilin B30 Firmware Multilin B90 Multilin B90 Firmware Multilin C30 Multilin C30 Firmware Multilin C60 Multilin C60 Firmware Multilin C70 Multilin C70 Firmware Multilin C95 Multilin C95 Firmware Multilin D30 Multilin D30 Firmware Multilin D60 Multilin D60 Firmware Multilin F35 Multilin F35 Firmware Multilin F60 Multilin F60 Firmware Multilin G30 Multilin G30 Firmware Multilin G60 Multilin G60 Firmware Multilin L30 Multilin L30 Firmware Multilin L60 Multilin L60 Firmware Multilin L90 Multilin L90 Firmware Multilin M60 Multilin M60 Firmware Multilin N60 Multilin N60 Firmware Multilin T35 Multilin T35 Firmware Multilin T60 Multilin T60 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-04-16T16:40:19.585Z

Reserved: 2021-02-19T00:00:00.000Z

Link: CVE-2021-27422

cve-icon Vulnrichment

Updated: 2024-08-03T20:48:17.116Z

cve-icon NVD

Status : Modified

Published: 2022-03-23T20:15:08.367

Modified: 2024-11-21T05:57:57.480

Link: CVE-2021-27422

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses