PT-2022-9815 · Ge · Ge Ur

Published

2022-03-23

·

Updated

2022-04-01

·

CVE-2021-27424

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GE UR firmware versions prior to 8.1x
Description The issue concerns the sharing of the MODBUS memory map as part of the communications guide in GE UR firmware. A "Last-key pressed" MODBUS register can be exploited to gain unauthorized information.
Recommendations For GE UR firmware versions prior to 8.1x, update to version 8.1x or later to resolve the issue. As a temporary workaround, consider restricting access to the MODBUS register to minimize the risk of exploitation.

Fix

Information Disclosure

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27424

Affected Products

Ge Ur