Information disclosure in GE products - CVE-2021-27422

 

Information disclosure in GE products - CVE-2021-27422

Published: March 17, 2021


Vulnerability identifier: #VU51525
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-27422
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the web server interface is supported on UR over HTTP protocol. A remote attacker can gain unauthorized access to sensitive information on the system.


Affected software

G30
T60
T35
N60
M60
L90
L60
L30
G60
B30
F60
F35
D60
D30
C95
C70
C60
C30

How to mitigate CVE-2021-27422

Install updates from vendor's website.

G30 - update to 8.10
T60 - update to 8.10
T35 - update to 8.10
N60 - update to 8.10
M60 - update to 8.10
L90 - update to 8.10
L60 - update to 8.10
L30 - update to 8.10
G60 - update to 8.10
B30 - update to 8.10
F60 - update to 8.10
F35 - update to 8.10
D60 - update to 8.10
D30 - update to 8.10
C95 - update to 8.10
C70 - update to 8.10
C60 - update to 8.10
C30 - update to 8.10

External References

Related Security Bulletins