IM
IronMonkey Threat Research

CVE-2023-4518 HIGH

Published: 2023-12-01 | Last Modified: 2024-11-21 | Status: Modified

Description

A vulnerability exists in the input validation of the GOOSE messages where out of range values received and processed by the IED caused a reboot of the device. In order for an attacker to exploit the vulnerability, goose receiving blocks need to be configured.

Additional Descriptions (1)

Existe una vulnerabilidad en la validación de entrada de los mensajes GOOSE donde los valores fuera de rango recibidos y procesados por el IED provocaron un reinicio del dispositivo. Para que un atacante aproveche la vulnerabilidad, es necesario configurar los bloques receptores de ganso.

CVSS Metrics

Base Score: 7.5 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-1284
[email protected] Primary
en CWE-1284

Affected Products

Vendor Product Version Update Type
hitachienergy relion_670_firmware * <built-in method update of dict object at 0x72a9b0ca6280> Operating System
hitachienergy relion_670_firmware * <built-in method update of dict object at 0x72a9b0d7b5c0> Operating System
hitachienergy relion_670_firmware * <built-in method update of dict object at 0x72a9b0a48f40> Operating System
hitachienergy relion_670_firmware * <built-in method update of dict object at 0x72a9b0a780c0> Operating System
hitachienergy relion_650_firmware * <built-in method update of dict object at 0x72a9b0ca6d80> Operating System
hitachienergy relion_650_firmware * <built-in method update of dict object at 0x72a9b0ca7780> Operating System
hitachienergy relion_650_firmware 2.2.1 <built-in method update of dict object at 0x72a9a39c67c0> Operating System
hitachienergy relion_650_firmware 2.2.1.6 <built-in method update of dict object at 0x72a9a39c5d40> Operating System
hitachienergy relion_sam600-io_firmware * <built-in method update of dict object at 0x72a9b0b755c0> Operating System
hitachienergy relion_sam600-io_firmware 2.2.1 <built-in method update of dict object at 0x72a9b0ca61c0> Operating System
hitachienergy relion_sam600-io_firmware 2.2.1.6 <built-in method update of dict object at 0x72a9b0a4a500> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:hitachienergy:relion_670_firmware:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:hitachienergy:relion_670_firmware:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:hitachienergy:relion_670_firmware:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:hitachienergy:relion_670_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:hitachienergy:relion_670:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:hitachienergy:relion_650_firmware:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:hitachienergy:relion_650_firmware:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:hitachienergy:relion_650_firmware:2.2.1:*:*:*:*:*:*:*
Yes cpe:2.3:o:hitachienergy:relion_650_firmware:2.2.1.6:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:hitachienergy:relion_650:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:hitachienergy:relion_sam600-io_firmware:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:hitachienergy:relion_sam600-io_firmware:2.2.1:*:*:*:*:*:*:*
Yes cpe:2.3:o:hitachienergy:relion_sam600-io_firmware:2.2.1.6:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:hitachienergy:relion_sam600-io:-:*:*:*:*:*:*:*
Notification
Message here