Vulnerability Details CVE-2021-27430
GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED can interrupt the boot sequence by rebooting the UR.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 25.6%
CVSS Severity
CVSS v3 Score 8.4
CVSS v2 Score 4.6
Products affected by CVE-2021-27430
-
cpe:2.3:a:ge:ur_bootloader_binary:7.00
-
cpe:2.3:a:ge:ur_bootloader_binary:7.01
-
cpe:2.3:a:ge:ur_bootloader_binary:7.02