GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a “Last-key pressed” MODBUS register can be used to gain unauthorized information.
Solution:
Workaround:
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-21-075-02 | us government resource third party advisory mitigation |
https://www.gegridsolutions.com/Passport/Login.aspx | permissions required vendor advisory |