CVE-2021-27424

MEDIUMCVSS 5.3/10EPSS 0.84%

Last modified

CVE-2021-27424 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a “Last-key pressed” MODBUS register can be used to gain unauthorized information.. EPSS estimates a 0.84% chance of exploitation in the next 30 days.

Description

GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a “Last-key pressed” MODBUS register can be used to gain unauthorized information.

Metrics

CVSS 3.1
5.3/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS Probability
0.84%

53.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
GeMultilin B30 Firmware< 8.10
GeMultilin B90 Firmware< 8.10
GeMultilin C60 Firmware< 8.10
GeMultilin C70 Firmware< 8.10
GeMultilin C95 Firmware< 8.10
GeMultilin D30 Firmware< 8.10
GeMultilin D60 Firmware< 8.10
GeMultilin F35 Firmware< 8.10
GeMultilin F60 Firmware< 8.10
GeMultilin G30 Firmware< 8.10
GeMultilin G60 Firmware< 8.10
GeMultilin L30 Firmware< 8.10
GeMultilin L60 Firmware< 8.10
GeMultilin L90 Firmware< 8.10
GeMultilin M60 Firmware< 8.10
GeMultilin N60 Firmware< 8.10
GeMultilin T35 Firmware< 8.10
GeMultilin T60 Firmware< 8.10
GeMultilin C30 Firmware< 8.10

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-27424?
GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a “Last-key pressed” MODBUS register can be used to gain unauthorized information.
How severe is CVE-2021-27424?
CVE-2021-27424 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 0.84% probability of exploitation in the next 30 days.
How do I fix CVE-2021-27424?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-27424?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST