CVE-2021-27422

HIGHCVSS 7.5/10EPSS 0.64%

Last modified

CVE-2021-27422 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.. EPSS estimates a 0.64% chance of exploitation in the next 30 days.

Description

GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.64%

46.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
GeMultilin B30 Firmware< 8.10
GeMultilin B90 Firmware< 8.10
GeMultilin C60 Firmware< 8.10
GeMultilin C70 Firmware< 8.10
GeMultilin C95 Firmware< 8.10
GeMultilin D30 Firmware< 8.10
GeMultilin D60 Firmware< 8.10
GeMultilin F35 Firmware< 8.10
GeMultilin F60 Firmware< 8.10
GeMultilin G30 Firmware< 8.10
GeMultilin G60 Firmware< 8.10
GeMultilin L30 Firmware< 8.10
GeMultilin L60 Firmware< 8.10
GeMultilin L90 Firmware< 8.10
GeMultilin M60 Firmware< 8.10
GeMultilin N60 Firmware< 8.10
GeMultilin T35 Firmware< 8.10
GeMultilin T60 Firmware< 8.10
GeMultilin C30 Firmware< 8.10

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-27422?
GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.
How severe is CVE-2021-27422?
CVE-2021-27422 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.64% probability of exploitation in the next 30 days.
How do I fix CVE-2021-27422?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-27422?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST