A vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED to restart. After restart the device is back to normal operation. An attacker could exploit the vulnerability by first gaining access to the system with security privileges and attempt to update the IED with a malicious update package. Successful exploitation of this vulnerability will cause the IED to restart, causing a temporary Denial of Service.
Existe una vulnerabilidad en la validación de la firma del paquete de actualización de Relion. Un paquete de actualización manipulado podría provocar que el IED se reinicie. Después de reiniciar, el dispositivo vuelve a su funcionamiento normal. Un atacante podría aprovechar la vulnerabilidad obteniendo primero acceso al sistema con privilegios de seguridad e intentando actualizar el IED con un paquete de actualización malicioso. La explotación exitosa de esta vulnerabilidad hará que el IED se reinicie, lo que provocará una denegación de servicio temporal.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | HIGH |
| User Interaction | REQUIRED |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | NONE |
| Availability Impact | HIGH |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-347
|
| [email protected] | Primary |
en
CWE-347
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| hitachienergy | relion_650_firmware | 2.2.0 | <built-in method update of dict object at 0x72a9b0aa4380> | Operating System |
| hitachienergy | relion_650_firmware | 2.2.1 | <built-in method update of dict object at 0x72a9cc874cc0> | Operating System |
| hitachienergy | relion_650_firmware | 2.2.4 | <built-in method update of dict object at 0x72a9cc8753c0> | Operating System |
| hitachienergy | relion_650_firmware | 2.2.5 | <built-in method update of dict object at 0x72a9cd087a00> | Operating System |
| hitachienergy | relion_670_firmware | 2.2.0 | <built-in method update of dict object at 0x72a9b0aa71c0> | Operating System |
| hitachienergy | relion_670_firmware | 2.2.1 | <built-in method update of dict object at 0x72a9b0aa4f40> | Operating System |
| hitachienergy | relion_670_firmware | 2.2.2 | <built-in method update of dict object at 0x72a9b0a74640> | Operating System |
| hitachienergy | relion_670_firmware | 2.2.3 | <built-in method update of dict object at 0x72a9b0b38300> | Operating System |
| hitachienergy | relion_670_firmware | 2.2.4 | <built-in method update of dict object at 0x72a9b0b69280> | Operating System |
| hitachienergy | relion_670_firmware | 2.2.5 | <built-in method update of dict object at 0x72a9b0aa4740> | Operating System |
| hitachienergy | relion_sam600-io_firmware | 2.2.1 | <built-in method update of dict object at 0x72a9cc877d00> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:hitachienergy:relion_650_firmware:2.2.0:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:relion_650_firmware:2.2.1:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:relion_650_firmware:2.2.4:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:relion_650_firmware:2.2.5:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:hitachienergy:relion_650:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:hitachienergy:relion_670_firmware:2.2.0:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:relion_670_firmware:2.2.1:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:relion_670_firmware:2.2.2:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:relion_670_firmware:2.2.3:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:relion_670_firmware:2.2.4:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:relion_670_firmware:2.2.5:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:hitachienergy:relion_670:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:hitachienergy:relion_sam600-io_firmware:2.2.1:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:hitachienergy:relion_sam600-io:-:*:*:*:*:*:*:* |