GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user.
Solution:
Workaround:
The product, by default, initializes an internal variable with an insecure or less secure value than is possible.
Link | Tags |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-21-075-02 | us government resource third party advisory mitigation |
https://www.gegridsolutions.com/Passport/Login.aspx | permissions required vendor advisory |