Lucene search

K
cveIcscertCVE-2019-18247
HistoryNov 27, 2019 - 11:15 p.m.

CVE-2019-18247

2019-11-2723:15:10
CWE-20
icscert
web.nvd.nist.gov
34
cve-2019-18247
relion 650
relion 670
denial of service
nvd
security vulnerability

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

41.5%

An attacker may use a specially crafted message to force Relion 650 series (versions 1.3.0.5 and prior) or Relion 670 series (versions 1.2.3.18, 2.0.0.11, 2.1.0.1 and prior) to reboot, which could cause a denial of service.

Affected configurations

Nvd
Node
hitachienergyrelion_650_firmwareRange1.3.0.5
AND
hitachienergyrelion_650Match-
Node
hitachienergyrelion_670_firmwareRange1.2.3.18
AND
hitachienergyrelion_670Match-
Node
hitachienergyrelion_670_firmwareRange2.0.02.0.0.11
AND
hitachienergyrelion_670Match-
Node
hitachienergyrelion_670_firmwareRange2.1.02.1.0.1
AND
hitachienergyrelion_670Match-
VendorProductVersionCPE
hitachienergyrelion_650_firmware*cpe:2.3:o:hitachienergy:relion_650_firmware:*:*:*:*:*:*:*:*
hitachienergyrelion_650-cpe:2.3:h:hitachienergy:relion_650:-:*:*:*:*:*:*:*
hitachienergyrelion_670_firmware*cpe:2.3:o:hitachienergy:relion_670_firmware:*:*:*:*:*:*:*:*
hitachienergyrelion_670-cpe:2.3:h:hitachienergy:relion_670:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Relion 650 and 670 Series",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Relion 650 series versions 1.3.0.5 and prior, Relion 670 series versions 1.2.3.18, 2.0.0.11, 2.1.0.1 and prior"
      }
    ]
  }
]

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

41.5%

Related for CVE-2019-18247