CVE Vulnerabilities

CVE-2021-27426

Insecure Default Variable Initialization

Published: Mar 23, 2022 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user.

Weakness

The product, by default, initializes an internal variable with an insecure or less secure value than is possible.

Affected Software

NameVendorStart VersionEnd Version
Multilin_b30_firmwareGe*8.10 (excluding)

Potential Mitigations

References