Use of hard-coded credentials in GE products - CVE-2021-27430
Published: March 17, 2021
Vulnerability identifier: #VU51531
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-27430
CWE-ID: CWE-798
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to gain full access to vulnerable system.
The vulnerability exists due to presence of hard-coded credentials in application code. A local attacker can interrupt the boot sequence by rebooting the UR.
Affected software
UR bootloader binary
G60
T60
T35
N60
M60
L90
L60
L30
B30
G30
F60
F35
D60
D30
C95
C70
C60
C30
G60
T60
T35
N60
M60
L90
L60
L30
B30
G30
F60
F35
D60
D30
C95
C70
C60
C30
How to mitigate CVE-2021-27430
Install updates from vendor's website.
UR bootloader binary - addressed in versions 7.03, 7.04
G60 - update to 8.10
T60 - update to 8.10
T35 - update to 8.10
N60 - update to 8.10
M60 - update to 8.10
L90 - update to 8.10
L60 - update to 8.10
L30 - update to 8.10
B30 - update to 8.10
G30 - update to 8.10
F60 - update to 8.10
F35 - update to 8.10
D60 - update to 8.10
D30 - update to 8.10
C95 - update to 8.10
C70 - update to 8.10
C60 - update to 8.10
C30 - update to 8.10
G60 - update to 8.10
T60 - update to 8.10
T35 - update to 8.10
N60 - update to 8.10
M60 - update to 8.10
L90 - update to 8.10
L60 - update to 8.10
L30 - update to 8.10
B30 - update to 8.10
G30 - update to 8.10
F60 - update to 8.10
F35 - update to 8.10
D60 - update to 8.10
D30 - update to 8.10
C95 - update to 8.10
C70 - update to 8.10
C60 - update to 8.10
C30 - update to 8.10