ICSA-21-075-02: Ge web server vulnerability
Affected Software
6 affected components
GE Vulnerabilities related to SSH Support: firmware versions 7.4x to 8.0x (CyberSentry option)
GE Web server vulnerabilities: all firmware versions prior to version 8.1x
GE Protection from unintended firmware upload: all firmware versions prior to 8.1x with basic security option
GE Provisions to disable Factory Mode: all firmware versions prior to 8.1x with basic security option
GE Access to “Last-key pressed” register: all firmware versions prior to 8.1x with basic security option
GE Weakness in UR bootloader binary: all bootloader versions prior to 7.03/7.04
Event History
Feb 22, 2025
Advisory Published
05:12 AM
Frequently Asked Questions
1
What is the severity of ICSA-21-075-02?
ICSA-21-075-02 has been rated with high severity due to multiple vulnerabilities that could lead to unauthorized access and potential system compromise.
2
How do I fix ICSA-21-075-02?
To fix ICSA-21-075-02, you should upgrade the firmware to version 8.1x or later for affected devices.
3
What vulnerabilities are identified in ICSA-21-075-02?
ICSA-21-075-02 identifies multiple vulnerabilities related to SSH support, web server security, firmware upload protections, and factory mode disablement across various GE products.
4
Who is affected by the vulnerabilities in ICSA-21-075-02?
Organizations using GE firmware versions 7.4x to 8.0x and all versions prior to 8.1x are at risk and need to address these vulnerabilities.
5
What types of devices are impacted by ICSA-21-075-02?
Impacted devices include those with GE firmware that support SSH, web servers, and basic security options that allow unintended firmware uploads.