GE Update
3006Warning Date
Severity Level
Warning Number
Target Sector
17 March, 2021
● Critical
2021-2636
Communication and information technology - Energy - Transportation - Water and Utilities - HealthCare - Manufacturing - Other
Description:
GE has released a security update to address several vulnerabilities in the following product:
- UR family (B30, B90, C30, C60, C70, C95, D30, D60, F35, F60, G30, G60, L30, L60, L90, M60, N60, T35, T60)
Threats:
Attacker could exploit this vulnerability by doing the following:
- Sensitive information disclosure
- Session Fixation
- Cross-site scripting (XSS)
Best practice and Recommendations:
The CERT team encourages users to review GE security advisory and apply the necessary updates: