CVE-2021-27424
Estado: ModificadaMedia (5.3)—
GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a “Last-key pressed” MODBUS register can be used to gain unauthorized information.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.88%
- Percentil entre todas las CVEs puntuadas: 58
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (19)
GE — Multilin B30 FirmwareGE — Multilin B90 FirmwareGE — Multilin C30 FirmwareGE — Multilin C60 FirmwareGE — Multilin C70 FirmwareGE — Multilin C95 FirmwareGE — Multilin D30 FirmwareGE — Multilin D60 FirmwareGE — Multilin F35 FirmwareGE — Multilin F60 FirmwareGE — Multilin G30 FirmwareGE — Multilin G60 FirmwareGE — Multilin L30 FirmwareGE — Multilin L60 FirmwareGE — Multilin L90 FirmwareGE — Multilin M60 FirmwareGE — Multilin N60 FirmwareGE — Multilin T35 FirmwareGE — Multilin T60 Firmware
CWE
- CWE-200
- CWE-668
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-27424",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2021-27424",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-04-16T15:59:10.663565Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "GE",
"product": "UR family",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "8.1x",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-03-23T20:15:08.417",
"references": [
{
"url": "https://www.cisa.gov/uscert/ics/advisories/icsa-21-075-02",
"tags": [
"Mitigation",
"Third Party Advisory",
"US Government Resource"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://www.gegridsolutions.com/Passport/Login.aspx",
"tags": [
"Permissions Required",
"Vendor Advisory"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://www.cisa.gov/uscert/ics/advisories/icsa-21-075-02",
"tags": [
"Mitigation",
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.gegridsolutions.com/Passport/Login.aspx",
"tags": [
"Permissions Required",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-668"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a “Last-key pressed” MODBUS register can be used to gain unauthorized information."
},
{
"lang": "es",
"value": "GE UR versiones de firmware anteriores a versión 8.1x, comparten el mapa de memoria MODBUS como parte de la guía de comunicaciones. GE se dio cuenta de que un registro MODBUS de \"última tecla pulsada\" puede usarse para obtener información no autorizada"
}
],
"lastModified": "2026-06-17T03:44:49.950",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ge:multilin_b30_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "971B98BB-125D-4D3F-8B54-09C6ECBEFC46",
"versionEndExcluding": "8.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ge:multilin_b30:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9AEAC84B-ED36-4D41-8CDC-84B30294667F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ge:multilin_b90_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F0DD7078-54B7-4908-B041-C389601FFE54",
"versionEndExcluding": "8.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ge:multilin_b90:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8F9FE28C-1F33-4ECA-9004-B46912A1D8D8"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ge:multilin_c60_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1A9D29A9-8351-48E0-BFCF-21945F586C51",
"versionEndExcluding": "8.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ge:multilin_c60:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F14E4B7C-E38E-4877-9EB6-BE496CFBB8D4"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ge:multilin_c70_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6AEDFEAA-FF6B-40AE-988D-96B37E6F7A15",
"versionEndExcluding": "8.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ge:multilin_c70:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5F2E81E6-B718-4809-8D30-3074B0FB7239"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ge:multilin_c95_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A6A8BC17-2B8A-4FCD-AED4-D60DBFA2CCAC",
"versionEndExcluding": "8.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ge:multilin_c95:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "AFD919B5-753E-40A8-8B14-BD0BA28386C7"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ge:multilin_d30_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A3506446-AF0D-4AC4-8C0A-5616D27C267B",
"versionEndExcluding": "8.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ge:multilin_d30:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9226C470-365B-4CFF-B1FF-326EA82E9C16"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ge:multilin_d60_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B0E5D2F8-AA89-44E3-9316-E28357E525D8",
"versionEndExcluding": "8.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ge:multilin_d60:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1CFC93A6-7FAB-4057-A962-6A9C8F0FD3DA"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ge:multilin_f35_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C86C0AEE-795B-45B1-A917-00A355EC25CD",
"versionEndExcluding": "8.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ge:multilin_f35:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B66B913C-6D8A-4B5E-92AF-0ABE67195C47"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ge:multilin_f60_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D151332D-37C7-4F7B-A30E-EB7F927B905D",
"versionEndExcluding": "8.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ge:multilin_f60:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "313C6A1D-B50A-40C5-8553-68F21DFEDDDC"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ge:multilin_g30_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D2E9423B-F49D-4AF7-8275-3216D615F279",
"versionEndExcluding": "8.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ge:multilin_g30:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BC9965C1-9B3C-4B8A-8643-43678B5A6643"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ge:multilin_g60_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2447F208-815E-44D2-91BC-7BFCFC85C977",
"versionEndExcluding": "8.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ge:multilin_g60:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "20A13929-C8B5-49E0-9F5C-EA443413C584"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ge:multilin_l30_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2DE2725C-8778-479D-8743-F62B5763931D",
"versionEndExcluding": "8.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ge:multilin_l30:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FF00D002-3C82-47B1-B585-DB91F33CEECC"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ge:multilin_l60_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "34B1A2B8-B43B-4CCD-886A-0487C09E5279",
"versionEndExcluding": "8.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ge:multilin_l60:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0F716F53-3AC6-41C6-A894-9712A8AFE58C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ge:multilin_l90_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "58A5CD1D-27C0-4D14-9FBE-A8C74BD9737B",
"versionEndExcluding": "8.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ge:multilin_l90:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7BFF5085-6713-41FA-93D5-65AE4C8F8AD1"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ge:multilin_m60_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E0B3453A-1B71-4ADD-8AC3-5D5436EAD879",
"versionEndExcluding": "8.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ge:multilin_m60:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5431E320-7E3A-4BD3-B33A-3345CF20B20D"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ge:multilin_n60_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "80DE8022-6349-4E53-B97B-AFAD1685E40E",
"versionEndExcluding": "8.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ge:multilin_n60:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2217A440-FADD-40ED-A933-F3DBCF36E116"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ge:multilin_t35_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "51F57944-8FDB-4541-A6ED-BF6D40916786",
"versionEndExcluding": "8.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ge:multilin_t35:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4B7B0753-62C7-4972-AD22-FC3E31A5218F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ge:multilin_t60_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B97E0654-4407-48CE-BC07-E2385E86B65A",
"versionEndExcluding": "8.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ge:multilin_t60:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5E75BD31-3057-42F4-BD1B-C68C797F39DF"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ge:multilin_c30_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "10F68AE0-E4FC-4357-A619-B0B990FDC708",
"versionEndExcluding": "8.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ge:multilin_c30:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "314AA92C-5B56-475A-B65F-CF597CEBFB38"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}