CVE-2021-27422

HIGH

GE Multilin UR Firmware < 8.10 - Unauthenticated Cleartext Transmission of Sensitive Information

Title source: llm
STIX 2.1

Description

GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.

References (2)

Core 2
Core References
Mitigation, Third Party Advisory, US Government Resource x_refsource_confirm
https://www.cisa.gov/uscert/ics/advisories/icsa-21-075-02
Permissions Required, Vendor Advisory x_refsource_confirm
https://www.gegridsolutions.com/Passport/Login.aspx

Scores

CVSS v3 7.5
EPSS 0.0064
EPSS Percentile 45.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-319 CWE-200
Status published
Products (19)
ge/multilin_b30_firmware < 8.10
ge/multilin_b90_firmware < 8.10
ge/multilin_c30_firmware < 8.10
ge/multilin_c60_firmware < 8.10
ge/multilin_c70_firmware < 8.10
ge/multilin_c95_firmware < 8.10
ge/multilin_d30_firmware < 8.10
ge/multilin_d60_firmware < 8.10
ge/multilin_f35_firmware < 8.10
ge/multilin_f60_firmware < 8.10
... and 9 more
Published Mar 23, 2022
Tracked Since Feb 18, 2026