The software contains a hard-coded password that could allow an attacker to take control of the merging unit using these hard-coded credentials on the MU320E (all firmware versions prior to v04A00.1).
References
Link | Resource |
---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-21-082-02 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2021-03-25 13:15
Updated : 2021-03-29 10:36
NVD link : CVE-2021-27452
Mitre link : CVE-2021-27452
JSON object : View
CWE
CWE-798
Use of Hard-coded Credentials
Products Affected
ge
- mu320e_firmware
- mu320e