First published: Thu Mar 25 2021(Updated: )
The software contains a hard-coded password that could allow an attacker to take control of the merging unit using these hard-coded credentials on the MU320E (all firmware versions prior to v04A00.1).
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Ge Mu320e Firmware | <04a00.1 | |
Ge Mu320e | ||
GE All firmware versions prior to v04A00.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27452 is a vulnerability in the Ge Mu320e firmware that contains a hard-coded password, allowing an attacker to take control of the merging unit.
CVE-2021-27452 has a severity rating of 7.8 (high).
All firmware versions prior to v04A00.1 of the Ge Mu320e firmware are affected by CVE-2021-27452.
An attacker can exploit CVE-2021-27452 by using the hard-coded credentials in the Mu320e firmware to take control of the merging unit.
No, the Ge Mu320e software itself is not vulnerable to CVE-2021-27452.