CVE-2021-27420 Information
Jun 07, 2022
cve
Description
GE UR firmware versions prior to version 8.1x web server task does not properly handle receipt of unsupported HTTP verbs resulting in the web server becoming temporarily unresponsive after receiving a series of unsupported HTTP requests. When unresponsive the web server is inaccessible. By itself this is not particularly significant as the relay remains effective in all other functionality and communication channels.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Reference
https://www.cisa.gov/uscert/ics/advisories/icsa-21-075-02 https://www.gegridsolutions.com/Passport/Login.aspx
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
LOW
Base Severity
5.3
Share on: