PT-2022-9815 · Ge · Ge Ur
Published
2022-03-23
·
Updated
2022-04-01
·
CVE-2021-27424
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GE UR firmware versions prior to 8.1x
Description
The issue concerns the sharing of the MODBUS memory map as part of the communications guide in GE UR firmware. A "Last-key pressed" MODBUS register can be exploited to gain unauthorized information.
Recommendations
For GE UR firmware versions prior to 8.1x, update to version 8.1x or later to resolve the issue. As a temporary workaround, consider restricting access to the MODBUS register to minimize the risk of exploitation.
Fix
Information Disclosure
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ge Ur