Insecure Default Variable Initialization in GE products - CVE-2021-27426

 

Insecure Default Variable Initialization in GE products - CVE-2021-27426

Published: March 17, 2021 / Updated: March 17, 2021


Vulnerability identifier: #VU51529
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-27426
CWE-ID: CWE-453
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to the UR IED with “Basic” security variant does not allow the disabling of the “Factory Mode", which is used for servicing the IED by a “Factory” user. A remote attacker who can execute arbitrary code on the system.

Note: This vulnerability affects the following versions of Provisions to disable Factory Mode:

  • all firmware versions prior to 8.1x with basic security option


Affected software

G30
T60
T35
N60
M60
L90
L60
L30
G60
B30
F60
F35
D60
D30
C95
C70
C60
C30

How to mitigate CVE-2021-27426

Install updates from vendor's website.

G30 - update to 8.10
T60 - update to 8.10
T35 - update to 8.10
N60 - update to 8.10
M60 - update to 8.10
L90 - update to 8.10
L60 - update to 8.10
L30 - update to 8.10
G60 - update to 8.10
B30 - update to 8.10
F60 - update to 8.10
F35 - update to 8.10
D60 - update to 8.10
D30 - update to 8.10
C95 - update to 8.10
C70 - update to 8.10
C60 - update to 8.10
C30 - update to 8.10

External References

Related Security Bulletins