CVE-2021-27420

MEDIUM

GE Multilin UR Series Firmware < 8.10 - Denial of Service via Unsupported HTTP Verb Handling

Title source: llm
STIX 2.1

Description

GE UR firmware versions prior to version 8.1x web server task does not properly handle receipt of unsupported HTTP verbs, resulting in the web server becoming temporarily unresponsive after receiving a series of unsupported HTTP requests. When unresponsive, the web server is inaccessible. By itself, this is not particularly significant as the relay remains effective in all other functionality and communication channels.

References (2)

Core 2
Core References
Mitigation, Third Party Advisory, US Government Resource x_refsource_confirm
https://www.cisa.gov/uscert/ics/advisories/icsa-21-075-02
Permissions Required, Vendor Advisory x_refsource_confirm
https://www.gegridsolutions.com/Passport/Login.aspx

Scores

CVSS v3 5.3
EPSS 0.0102
EPSS Percentile 59.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (19)
ge/multilin_b30_firmware < 8.10
ge/multilin_b90_firmware < 8.10
ge/multilin_c30_firmware < 8.10
ge/multilin_c60_firmware < 8.10
ge/multilin_c70_firmware < 8.10
ge/multilin_c95_firmware < 8.10
ge/multilin_d30_firmware < 8.10
ge/multilin_d60_firmware < 8.10
ge/multilin_f35_firmware < 8.10
ge/multilin_f60_firmware < 8.10
... and 9 more
Published Mar 23, 2022
Tracked Since Feb 18, 2026