CVE-2021-27430

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
23/03/2022
Last modified:
31/03/2022

Description

GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED can interrupt the boot sequence by rebooting the UR.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ge:ur_bootloader_binary:7.00:*:*:*:*:*:*:*
cpe:2.3:a:ge:ur_bootloader_binary:7.01:*:*:*:*:*:*:*
cpe:2.3:a:ge:ur_bootloader_binary:7.02:*:*:*:*:*:*:*