2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2021-27430" ,
"sourceIdentifier" : "ics-cert@hq.dhs.gov" ,
"published" : "2022-03-23T20:15:08.587" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T05:57:58.487" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED can interrupt the boot sequence by rebooting the UR."
} ,
{
"lang" : "es" ,
"value" : "Las versiones 7.00, 7.01 y 7.02 del binario del cargador de arranque GE UR inclu\u00edan credenciales embebidas no usadas. Adem\u00e1s, un usuario con acceso f\u00edsico al IED de la UR puede interrumpir la secuencia de arranque al reiniciar la UR"
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
2024-12-08 03:06:42 +00:00
"source" : "ics-cert@hq.dhs.gov" ,
"type" : "Secondary" ,
2023-04-24 12:24:31 +02:00
"cvssData" : {
"version" : "3.1" ,
2024-12-08 03:06:42 +00:00
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
"baseScore" : 8.4 ,
"baseSeverity" : "HIGH" ,
"attackVector" : "LOCAL" ,
2023-04-24 12:24:31 +02:00
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2023-04-24 12:24:31 +02:00
} ,
2024-12-08 03:06:42 +00:00
"exploitabilityScore" : 2.5 ,
2023-04-24 12:24:31 +02:00
"impactScore" : 5.9
} ,
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-04-24 12:24:31 +02:00
"cvssData" : {
"version" : "3.1" ,
2024-12-08 03:06:42 +00:00
"vectorString" : "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
"baseScore" : 6.8 ,
"baseSeverity" : "MEDIUM" ,
"attackVector" : "PHYSICAL" ,
2023-04-24 12:24:31 +02:00
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2023-04-24 12:24:31 +02:00
} ,
2024-12-08 03:06:42 +00:00
"exploitabilityScore" : 0.9 ,
2023-04-24 12:24:31 +02:00
"impactScore" : 5.9
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 4.6 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "LOCAL" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "PARTIAL" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "PARTIAL"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 6.4 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
2024-12-08 03:06:42 +00:00
"source" : "ics-cert@hq.dhs.gov" ,
"type" : "Secondary" ,
2023-04-24 12:24:31 +02:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-798"
}
]
} ,
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-04-24 12:24:31 +02:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-798"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ge:ur_bootloader_binary:7.00:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "22714AED-DF46-46A3-B2E4-F12067B98D31"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ge:ur_bootloader_binary:7.01:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "27CA69B0-2830-4867-A471-65B3F411D3FA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ge:ur_bootloader_binary:7.02:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "74EAD676-32C8-443B-88B0-CC8EE8B15E95"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://www.cisa.gov/uscert/ics/advisories/icsa-21-075-02" ,
"source" : "ics-cert@hq.dhs.gov" ,
"tags" : [
"Mitigation" ,
"Third Party Advisory" ,
"US Government Resource"
]
} ,
{
"url" : "https://www.gegridsolutions.com/Passport/Login.aspx" ,
"source" : "ics-cert@hq.dhs.gov" ,
"tags" : [
"Permissions Required" ,
"Vendor Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://www.cisa.gov/uscert/ics/advisories/icsa-21-075-02" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Mitigation" ,
"Third Party Advisory" ,
"US Government Resource"
]
} ,
{
"url" : "https://www.gegridsolutions.com/Passport/Login.aspx" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Permissions Required" ,
"Vendor Advisory"
]
2023-04-24 12:24:31 +02:00
}
]
}