#VU51528 Arbitrary file upload in GE products - CVE-2021-27428
Published: March 17, 2021
Vulnerability identifier: #VU51528
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-27428
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
B30
C30
C60
C70
C95
D30
D60
F35
F60
G30
G60
L30
L60
L90
M60
N60
T35
T60
B30
C30
C60
C70
C95
D30
D60
F35
F60
G30
G60
L30
L60
L90
M60
N60
T35
T60
Software vendor:
GE
GE
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to the UR Setup tool validates the authenticity and integrity of firmware file before uploading the UR IED. A remote attacker can upgrade firmware without appropriate privileges.
Remediation
Install updates from vendor's website.