CVE-2021-27426

CRITICALCVSS 9.8/10EPSS 1.16%

Last modified

CVE-2021-27426 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user.. EPSS estimates a 1.16% chance of exploitation in the next 30 days.

Description

GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
1.16%

63.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
GeMultilin B30 Firmware< 8.10
GeMultilin B90 Firmware< 8.10
GeMultilin C60 Firmware< 8.10
GeMultilin C70 Firmware< 8.10
GeMultilin C95 Firmware< 8.10
GeMultilin D30 Firmware< 8.10
GeMultilin D60 Firmware< 8.10
GeMultilin F35 Firmware< 8.10
GeMultilin F60 Firmware< 8.10
GeMultilin G30 Firmware< 8.10
GeMultilin G60 Firmware< 8.10
GeMultilin L30 Firmware< 8.10
GeMultilin L60 Firmware< 8.10
GeMultilin L90 Firmware< 8.10
GeMultilin M60 Firmware< 8.10
GeMultilin N60 Firmware< 8.10
GeMultilin T35 Firmware< 8.10
GeMultilin T60 Firmware< 8.10
GeMultilin C30 Firmware< 8.10

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-27426?
GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user.
How severe is CVE-2021-27426?
CVE-2021-27426 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 1.16% probability of exploitation in the next 30 days.
How do I fix CVE-2021-27426?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-27426?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST