Lucene search

K
cve[email protected]CVE-2021-27196
HistoryJun 14, 2021 - 10:15 p.m.

CVE-2021-27196

2021-06-1422:15:11
CWE-20
web.nvd.nist.gov
47
2
cve
2021
27196
hitachi abb
power grids
relion 670 series
relion 650 series
iec 61850
network
vulnerability
input validation

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.4 High

AI Score

Confidence

High

0.009 Low

EPSS

Percentile

82.5%

Improper Input Validation vulnerability in Hitachi ABB Power Grids Relion 670 Series, Relion 670/650 Series, Relion 670/650/SAM600-IO, Relion 650, REB500, RTU500 Series, FOX615 (TEGO1), MSM, GMS600, PWC600 allows an attacker with access to the IEC 61850 network with knowledge of how to reproduce the attack, as well as the IP addresses of the different IEC 61850 access points (of IEDs/products), to force the device to reboot, which renders the device inoperable for approximately 60 seconds. This vulnerability affects only products with IEC 61850 interfaces. This issue affects: Hitachi ABB Power Grids Relion 670 Series 1.1; 1.2.3 versions prior to 1.2.3.20; 2.0 versions prior to 2.0.0.13; 2.1; 2.2.2 versions prior to 2.2.2.3; 2.2.3 versions prior to 2.2.3.2. Hitachi ABB Power Grids Relion 670/650 Series 2.2.0 versions prior to 2.2.0.13. Hitachi ABB Power Grids Relion 670/650/SAM600-IO 2.2.1 versions prior to 2.2.1.6. Hitachi ABB Power Grids Relion 650 1.1; 1.2; 1.3 versions prior to 1.3.0.7. Hitachi ABB Power Grids REB500 7.3; 7.4; 7.5; 7.6; 8.2; 8.3. Hitachi ABB Power Grids RTU500 Series 7.x version 7.x and prior versions; 8.x version 8.x and prior versions; 9.x version 9.x and prior versions; 10.x version 10.x and prior versions; 11.x version 11.x and prior versions; 12.x version 12.x and prior versions. Hitachi ABB Power Grids FOX615 (TEGO1) R1D02 version R1D02 and prior versions. Hitachi ABB Power Grids MSM 2.1.0 versions prior to 2.1.0. Hitachi ABB Power Grids GMS600 1.3.0 version 1.3.0 and prior versions. Hitachi ABB Power Grids PWC600 1.0 versions prior to 1.0.1.4; 1.1 versions prior to 1.1.0.1.

Affected configurations

NVD
Node
hitachienergyrelion_670Match-
AND
hitachienergyrelion_670_firmwareRange1.2.31.2.3.20
OR
hitachienergyrelion_670_firmwareRange2.02.0.0.13
OR
hitachienergyrelion_670_firmwareRange2.2.02.2.0.13
OR
hitachienergyrelion_670_firmwareRange2.2.12.2.1.6
OR
hitachienergyrelion_670_firmwareRange2.2.22.2.2.3
OR
hitachienergyrelion_670_firmwareRange2.2.32.2.3.2
OR
hitachienergyrelion_670_firmwareMatch1.1
OR
hitachienergyrelion_670_firmwareMatch2.1
Node
hitachienergyrelion_650Match-
AND
hitachienergyrelion_650_firmwareRange1.31.3.0.7
OR
hitachienergyrelion_650_firmwareRange2.2.02.2.0.13
OR
hitachienergyrelion_650_firmwareRange2.2.12.2.1.6
OR
hitachienergyrelion_650_firmwareMatch1.1
OR
hitachienergyrelion_650_firmwareMatch1.2
OR
hitachienergyrelion_650_firmwareMatch2.1
Node
hitachienergyrelion_sam600-ioMatch-
AND
hitachienergyrelion_sam600-io_firmwareRange2.2.12.2.1.6
Node
hitachienergyrtu500Match-
AND
hitachienergyrtu500_firmwareMatch7.0
OR
hitachienergyrtu500_firmwareMatch8.0
OR
hitachienergyrtu500_firmwareMatch9.0
OR
hitachienergyrtu500_firmwareMatch10.0
OR
hitachienergyrtu500_firmwareMatch11.0
OR
hitachienergyrtu500_firmwareMatch12.0
Node
hitachienergyreb500Match-
AND
hitachienergyreb500_firmwareRange7.37.60.19
OR
hitachienergyreb500_firmwareRange8.28.2.0.5
OR
hitachienergyreb500_firmwareRange8.38.3.1.0
Node
hitachienergyfox615_tego1Match-
AND
hitachienergyfox615_tego1_firmwareRange<r2a16
Node
hitachienergymodular_switchgear_monitoringMatch-
AND
hitachienergymodular_switchgear_monitoring_firmwareRange<2.1.0
Node
hitachienergygms600Match-
AND
hitachienergygms600_firmwareRange1.3.0
Node
hitachienergypwc600_firmwareRange1.01.0.1.4
OR
hitachienergypwc600_firmwareRange1.11.1.0.1
AND
hitachienergypwc600Match-

Social References

More

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.4 High

AI Score

Confidence

High

0.009 Low

EPSS

Percentile

82.5%

Related for CVE-2021-27196