CVE-2021-27420 PUBLISHED CVSS 5.300000190734863 MEDIUM

GE UR firmware versions prior to version 8.1x web server task does not properly handle receipt of unsupported HTTP verbs, resulting in the web server becoming temporarily unresponsive after receiving a series of unsupported HTTP requests. When unresponsive, the web server is inaccessible. By itself, this is not particularly significant as the relay remains effective in all other functionality and communication channels.

EPSS 0.23% · 45.7th percentile

Risk Scores

CVSS v3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS Score
0.23%
45.7th percentile

Affected Products

VendorProductVersions
GEUR family*
gemultilin_f35_firmware0
gemultilin_g60_firmware0
gemultilin_m60_firmware0
gemultilin_b30_firmware0
gemultilin_c70_firmware0
gemultilin_c30_firmware0
gemultilin_f60_firmware0
gemultilin_t35_firmware0
gemultilin_l30_firmware0
gemultilin_d30_firmware0
gemultilin_b90_firmware0
gemultilin_l60_firmware0
gemultilin_g30_firmware0
gemultilin_l90_firmware0
gemultilin_d60_firmware0
gemultilin_t60_firmware0
gemultilin_n60_firmware0
gemultilin_c95_firmware0
gemultilin_c60_firmware0

Timeline

References

Open in Interactive Console →