CVE-2021-27422

EUVD-2021-14176
GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
icscertCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 26%
Affected Products (NVD)
VendorProductVersion
gemultilin_b30_firmware
𝑥
< 8.10
gemultilin_b90_firmware
𝑥
< 8.10
gemultilin_c60_firmware
𝑥
< 8.10
gemultilin_c70_firmware
𝑥
< 8.10
gemultilin_c95_firmware
𝑥
< 8.10
gemultilin_d30_firmware
𝑥
< 8.10
gemultilin_d60_firmware
𝑥
< 8.10
gemultilin_f35_firmware
𝑥
< 8.10
gemultilin_f60_firmware
𝑥
< 8.10
gemultilin_g30_firmware
𝑥
< 8.10
gemultilin_g60_firmware
𝑥
< 8.10
gemultilin_l30_firmware
𝑥
< 8.10
gemultilin_l60_firmware
𝑥
< 8.10
gemultilin_l90_firmware
𝑥
< 8.10
gemultilin_m60_firmware
𝑥
< 8.10
gemultilin_n60_firmware
𝑥
< 8.10
gemultilin_t35_firmware
𝑥
< 8.10
gemultilin_t60_firmware
𝑥
< 8.10
gemultilin_c30_firmware
𝑥
< 8.10
𝑥
= Vulnerable software versions