CVE-2021-27428: GE UR family Unrestricted Upload of File with Dangerous Type
GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of firmware file before uploading the UR IED. An illegitimate user could upgrade firmware without appropriate privileges. The weakness is assessed, and mitigation is implemented in firmware Version 8.10.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-27428?
CVE-2021-27428 is a vulnerability that affects GE UR IED firmware versions prior to version 8.1x.
How does CVE-2021-27428 impact GE UR IED firmware?
CVE-2021-27428 allows illegitimate users to upgrade firmware without proper validation, potentially compromising the authenticity and integrity of the firmware file.
What is the severity of CVE-2021-27428?
CVE-2021-27428 has a severity rating of 9.8 (Critical).
How can I fix CVE-2021-27428?
To fix CVE-2021-27428, users should update their GE UR IED firmware to version 8.1x or later.
Where can I find more information about CVE-2021-27428?
More information about CVE-2021-27428 can be found at the following references: [CISA Advisory](https://www.cisa.gov/uscert/ics/advisories/icsa-21-075-02) and [GE Grid Solutions](https://www.gegridsolutions.com/Passport/Login.aspx).