SB2021032409 - Multiple vulnerabilities in GE MU320E



SB2021032409 - Multiple vulnerabilities in GE MU320E

Published: March 24, 2021

Security Bulletin ID SB2021032409
Severity
High
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 33% Low 67%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Use of Hard-coded Password (CVE-ID: CVE-2021-27452)

The vulnerability allows a remote attacker to compromise the target system. 

The vulnerability exists due to the software contains a hard-coded password. A remote attacker can take control of the merging unit using these hard-coded credentials.


2) Execution with unnecessary privileges (CVE-ID: CVE-2021-27448)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a miscommunication in the file system. A local user can gain elevated privileges on the target system.


3) Inadequate Encryption Strength (CVE-ID: CVE-2021-27450)

The vulnerability allows a local administrator to compromise the target system.

The vulnerability exists due to the SSH server configuration file does not implement some best practices, which can lead to additional misconfiguration or be leveraged as part of a larger attack.


Remediation

Install update from vendor's website.