CVE Vulnerabilities

CVE-2021-27426

Insecure Default Variable Initialization

Published: Mar 23, 2022 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user.

Weakness

The product, by default, initializes an internal variable with an insecure or less secure value than is possible.

Affected Software

Name Vendor Start Version End Version
Multilin_b30_firmware Ge * 8.10 (excluding)

Potential Mitigations

References