Description
GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a “Last-key pressed” MODBUS register can be used to gain unauthorized information.
Published: 2022-03-23
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10, or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 (login required).


Vendor Workaround

GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place. GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-14178 GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a “Last-key pressed” MODBUS register can be used to gain unauthorized information.
History

Wed, 16 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Ge Multilin B30 Multilin B30 Firmware Multilin B90 Multilin B90 Firmware Multilin C30 Multilin C30 Firmware Multilin C60 Multilin C60 Firmware Multilin C70 Multilin C70 Firmware Multilin C95 Multilin C95 Firmware Multilin D30 Multilin D30 Firmware Multilin D60 Multilin D60 Firmware Multilin F35 Multilin F35 Firmware Multilin F60 Multilin F60 Firmware Multilin G30 Multilin G30 Firmware Multilin G60 Multilin G60 Firmware Multilin L30 Multilin L30 Firmware Multilin L60 Multilin L60 Firmware Multilin L90 Multilin L90 Firmware Multilin M60 Multilin M60 Firmware Multilin N60 Multilin N60 Firmware Multilin T35 Multilin T35 Firmware Multilin T60 Multilin T60 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-04-16T16:40:47.222Z

Reserved: 2021-02-19T00:00:00.000Z

Link: CVE-2021-27424

cve-icon Vulnrichment

Updated: 2024-08-03T20:48:17.121Z

cve-icon NVD

Status : Modified

Published: 2022-03-23T20:15:08.417

Modified: 2024-11-21T05:57:57.660

Link: CVE-2021-27424

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses