CVE-2021-27426

critical

Description

GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user.

References

https://www.gegridsolutions.com/Passport/Login.aspx

https://www.cisa.gov/uscert/ics/advisories/icsa-21-075-02

Details

Source: Mitre, NVD

Published: 2022-03-23

Updated: 2022-04-01

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00428