GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED can interrupt the boot sequence by rebooting the UR.
2022-03-23T20:15:08.587
2024-11-21T05:57:58.487
Modified
CVSSv3.1: 8.4 (HIGH)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ge | ur_bootloader_binary | 7.00 | Yes |
Application | ge | ur_bootloader_binary | 7.01 | Yes |
Application | ge | ur_bootloader_binary | 7.02 | Yes |