CVE-2021-27422
23.03.2022, 20:15
GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.Enginsight
Vendor | Product | Version |
---|---|---|
ge | multilin_b30_firmware | 𝑥 < 8.10 |
ge | multilin_b90_firmware | 𝑥 < 8.10 |
ge | multilin_c60_firmware | 𝑥 < 8.10 |
ge | multilin_c70_firmware | 𝑥 < 8.10 |
ge | multilin_c95_firmware | 𝑥 < 8.10 |
ge | multilin_d30_firmware | 𝑥 < 8.10 |
ge | multilin_d60_firmware | 𝑥 < 8.10 |
ge | multilin_f35_firmware | 𝑥 < 8.10 |
ge | multilin_f60_firmware | 𝑥 < 8.10 |
ge | multilin_g30_firmware | 𝑥 < 8.10 |
ge | multilin_g60_firmware | 𝑥 < 8.10 |
ge | multilin_l30_firmware | 𝑥 < 8.10 |
ge | multilin_l60_firmware | 𝑥 < 8.10 |
ge | multilin_l90_firmware | 𝑥 < 8.10 |
ge | multilin_m60_firmware | 𝑥 < 8.10 |
ge | multilin_n60_firmware | 𝑥 < 8.10 |
ge | multilin_t35_firmware | 𝑥 < 8.10 |
ge | multilin_t60_firmware | 𝑥 < 8.10 |
ge | multilin_c30_firmware | 𝑥 < 8.10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-319 - Cleartext Transmission of Sensitive InformationThe software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.