Arbitrary file upload in GE products - CVE-2021-27428

 

Arbitrary file upload in GE products - CVE-2021-27428

Published: March 17, 2021


Vulnerability identifier: #VU51528
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-27428
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to the UR Setup tool validates the authenticity and integrity of firmware file before uploading the UR IED. A remote attacker can upgrade firmware without appropriate privileges.


Affected software

G30
T60
T35
N60
M60
L90
L60
L30
G60
B30
F60
F35
D60
D30
C95
C70
C60
C30

How to mitigate CVE-2021-27428

Install updates from vendor's website.

G30 - update to 8.10
T60 - update to 8.10
T35 - update to 8.10
N60 - update to 8.10
M60 - update to 8.10
L90 - update to 8.10
L60 - update to 8.10
L30 - update to 8.10
G60 - update to 8.10
B30 - update to 8.10
F60 - update to 8.10
F35 - update to 8.10
D60 - update to 8.10
D30 - update to 8.10
C95 - update to 8.10
C70 - update to 8.10
C60 - update to 8.10
C30 - update to 8.10

External References

Related Security Bulletins