Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-27418


GE UR firmware versions prior to version 8.1x supports web interface with read-only access. The device fails to properly validate user input, making it possible to perform cross-site scripting attacks, which may be used to send a malicious script. Also, UR Firmware web server does not perform HTML encoding of user-supplied strings.


Published

2022-03-23T20:15:08.247

Last Modified

2024-11-21T05:57:56.947

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System ge multilin_b30_firmware < 8.10 Yes
Hardware ge multilin_b30 - No
Operating System ge multilin_b90_firmware < 8.10 Yes
Hardware ge multilin_b90 - No
Operating System ge multilin_c60_firmware < 8.10 Yes
Hardware ge multilin_c60 - No
Operating System ge multilin_c70_firmware < 8.10 Yes
Hardware ge multilin_c70 - No
Operating System ge multilin_c95_firmware < 8.10 Yes
Hardware ge multilin_c95 - No
Operating System ge multilin_d30_firmware < 8.10 Yes
Hardware ge multilin_d30 - No
Operating System ge multilin_d60_firmware < 8.10 Yes
Hardware ge multilin_d60 - No
Operating System ge multilin_f35_firmware < 8.10 Yes
Hardware ge multilin_f35 - No
Operating System ge multilin_f60_firmware < 8.10 Yes
Hardware ge multilin_f60 - No
Operating System ge multilin_g30_firmware < 8.10 Yes
Hardware ge multilin_g30 - No
Operating System ge multilin_g60_firmware < 8.10 Yes
Hardware ge multilin_g60 - No
Operating System ge multilin_l30_firmware < 8.10 Yes
Hardware ge multilin_l30 - No
Operating System ge multilin_l60_firmware < 8.10 Yes
Hardware ge multilin_l60 - No
Operating System ge multilin_l90_firmware < 8.10 Yes
Hardware ge multilin_l90 - No
Operating System ge multilin_m60_firmware < 8.10 Yes
Hardware ge multilin_m60 - No
Operating System ge multilin_n60_firmware < 8.10 Yes
Hardware ge multilin_n60 - No
Operating System ge multilin_t35_firmware < 8.10 Yes
Hardware ge multilin_t35 - No
Operating System ge multilin_t60_firmware < 8.10 Yes
Hardware ge multilin_t60 - No
Operating System ge multilin_c30_firmware < 8.10 Yes
Hardware ge multilin_c30 - No

References