GE UR firmware versions prior to version 8.1x web server task does not properly handle receipt of unsupported HTTP verbs, resulting in the web server becoming temporarily unresponsive after receiving a series of unsupported HTTP requests. When unresponsive, the web server is inaccessible. By itself, this is not particularly significant as the relay remains effective in all other functionality and communication channels.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-21-075-02 Mitigation Third Party Advisory US Government Resource
https://www.gegridsolutions.com/Passport/Login.aspx Permissions Required Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: icscert

Published: 2022-03-23T19:46:24

Updated: 2022-03-23T19:46:24

Reserved: 2021-02-19T00:00:00


Link: CVE-2021-27420

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-03-23T20:15:08.310

Modified: 2022-04-01T18:25:19.887


Link: CVE-2021-27420

JSON object: View

cve-icon Redhat Information

No data.

CWE