A vulnerability exists in the input validation of the GOOSE messages where out of range values received and processed by the IED caused a reboot of the device. In order for an attacker to exploit the vulnerability, goose receiving blocks need to be configured.
Existe una vulnerabilidad en la validación de entrada de los mensajes GOOSE donde los valores fuera de rango recibidos y procesados por el IED provocaron un reinicio del dispositivo. Para que un atacante aproveche la vulnerabilidad, es necesario configurar los bloques receptores de ganso.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | NONE |
| Availability Impact | HIGH |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-1284
|
| [email protected] | Primary |
en
CWE-1284
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| hitachienergy | relion_670_firmware | * | <built-in method update of dict object at 0x72a9b0ca6280> | Operating System |
| hitachienergy | relion_670_firmware | * | <built-in method update of dict object at 0x72a9b0d7b5c0> | Operating System |
| hitachienergy | relion_670_firmware | * | <built-in method update of dict object at 0x72a9b0a48f40> | Operating System |
| hitachienergy | relion_670_firmware | * | <built-in method update of dict object at 0x72a9b0a780c0> | Operating System |
| hitachienergy | relion_650_firmware | * | <built-in method update of dict object at 0x72a9b0ca6d80> | Operating System |
| hitachienergy | relion_650_firmware | * | <built-in method update of dict object at 0x72a9b0ca7780> | Operating System |
| hitachienergy | relion_650_firmware | 2.2.1 | <built-in method update of dict object at 0x72a9a39c67c0> | Operating System |
| hitachienergy | relion_650_firmware | 2.2.1.6 | <built-in method update of dict object at 0x72a9a39c5d40> | Operating System |
| hitachienergy | relion_sam600-io_firmware | * | <built-in method update of dict object at 0x72a9b0b755c0> | Operating System |
| hitachienergy | relion_sam600-io_firmware | 2.2.1 | <built-in method update of dict object at 0x72a9b0ca61c0> | Operating System |
| hitachienergy | relion_sam600-io_firmware | 2.2.1.6 | <built-in method update of dict object at 0x72a9b0a4a500> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:hitachienergy:relion_670_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:relion_670_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:relion_670_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:relion_670_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:hitachienergy:relion_670:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:hitachienergy:relion_650_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:relion_650_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:relion_650_firmware:2.2.1:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:relion_650_firmware:2.2.1.6:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:hitachienergy:relion_650:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:hitachienergy:relion_sam600-io_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:relion_sam600-io_firmware:2.2.1:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:relion_sam600-io_firmware:2.2.1.6:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:hitachienergy:relion_sam600-io:-:*:*:*:*:*:*:* |