Information disclosure in GE products - CVE-2021-27424
Published: March 17, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the UR shares MODBUS memory map as part of the communications guide. A remote attacker can gain unauthorized access to sensitive information on the system.
Note: This vulnerability affects the following versions of Access to “Last-key pressed” register:
- all firmware versions prior to 8.1x with basic security option
Affected software
T60
T35
N60
M60
L90
L60
L30
G60
B30
F60
F35
D60
D30
C95
C70
C60
C30
How to mitigate CVE-2021-27424
T60 - update to 8.10
T35 - update to 8.10
N60 - update to 8.10
M60 - update to 8.10
L90 - update to 8.10
L60 - update to 8.10
L30 - update to 8.10
G60 - update to 8.10
B30 - update to 8.10
F60 - update to 8.10
F35 - update to 8.10
D60 - update to 8.10
D30 - update to 8.10
C95 - update to 8.10
C70 - update to 8.10
C60 - update to 8.10
C30 - update to 8.10