Lucene search

K
cvelistABBCVELIST:CVE-2021-22283
HistoryFeb 28, 2023 - 4:21 a.m.

CVE-2021-22283 MMS File Transfer Vulnerability impact on Distribution Automation products

2023-02-2804:21:41
CWE-665
ABB
www.cve.org
cve-2021-22283
mms file transfer
abb relion
vulnerability
distribution automation
improper initialization
communication channel manipulation

6.2 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

9.2%

Improper Initialization vulnerability in ABB Relion protection relays - 611 series, ABB Relion protection relays - 615 series IEC 4.0 FP1, ABB Relion protection relays - 615 series CN 4.0 FP1, ABB Relion protection relays - 615 series IEC 5.0, ABB Relion protection relays - 615 series IEC 5.0 FP1, ABB Relion protection relays - 620 series IEC/CN 2.0, ABB Relion protection relays - 620 series IEC/CN 2.0 FP1, ABB Relion protection relays - REX640 PCL1, ABB Relion protection relays - REX640 PCL2, ABB Relion protection relays - REX640 PCL3, ABB Relion protection relays - RER615, ABB Remote Monitoring and Control - REC615, ABB Merging Unit- SMU615 allows Communication Channel Manipulation.This issue affects Relion protection relays - 611 series: from 1.0.0 before 2.0.3; Relion protection relays - 615 series IEC 4.0 FP1: from 4.1.0 before 4.1.9; Relion protection relays - 615 series CN 4.0 FP1: from 4.1.0 before 4.1.8; Relion protection relays - 615 series IEC 5.0: from 5.0.0 before 5.0.12; Relion protection relays - 615 series IEC 5.0 FP1: from 5.1.0 before 5.1.20; Relion protection relays - 620 series IEC/CN 2.0: from 2.0.0 before 2.0.11; Relion protection relays - 620 series IEC/CN 2.0 FP1: from 2.1.0 before 2.1.15; Relion protection relays - REX640 PCL1: from 1.0.0 before 1.0.8; Relion protection relays - REX640 PCL2: from 1.1.0 before 1.1.4; Relion protection relays - REX640 PCL3: from 1.2.0 before 1.2.1; Relion protection relays - RER615: from 2.0.0 before 2.0.3; Remote Monitoring and Control - REC615: from 1.0.0 before 2.0.3; Merging Unit- SMU615: from 1.0.0 before 1.0.2.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Relion protection relays - 611 series",
    "vendor": "ABB",
    "versions": [
      {
        "lessThan": "2.0.3",
        "status": "affected",
        "version": "1.0.0",
        "versionType": "firmware"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Relion protection relays - 615 series IEC 4.0 FP1",
    "vendor": "ABB",
    "versions": [
      {
        "lessThan": " 4.1.9",
        "status": "affected",
        "version": "4.1.0",
        "versionType": "firmware"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Relion protection relays - 615 series CN 4.0 FP1",
    "vendor": "ABB",
    "versions": [
      {
        "lessThan": "4.1.8",
        "status": "affected",
        "version": "4.1.0",
        "versionType": "firmware"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Relion protection relays - 615 series IEC 5.0",
    "vendor": "ABB",
    "versions": [
      {
        "lessThan": "5.0.12",
        "status": "affected",
        "version": "5.0.0",
        "versionType": "firmware"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Relion protection relays - 615 series IEC 5.0 FP1",
    "vendor": "ABB",
    "versions": [
      {
        "lessThan": "5.1.20",
        "status": "affected",
        "version": "5.1.0",
        "versionType": "firmware"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Relion protection relays - 620 series IEC/CN 2.0",
    "vendor": "ABB",
    "versions": [
      {
        "lessThan": "2.0.11",
        "status": "affected",
        "version": "2.0.0",
        "versionType": "firmware"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Relion protection relays - 620 series IEC/CN 2.0 FP1",
    "vendor": "ABB",
    "versions": [
      {
        "lessThan": "2.1.15",
        "status": "affected",
        "version": "2.1.0",
        "versionType": "firmware"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Relion protection relays - REX640 PCL1",
    "vendor": "ABB",
    "versions": [
      {
        "lessThan": "1.0.8",
        "status": "affected",
        "version": "1.0.0",
        "versionType": "firmware"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Relion protection relays - REX640 PCL2",
    "vendor": "ABB",
    "versions": [
      {
        "lessThan": "1.1.4",
        "status": "affected",
        "version": "1.1.0",
        "versionType": "firmware"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Relion protection relays - REX640 PCL3",
    "vendor": "ABB",
    "versions": [
      {
        "lessThan": "1.2.1",
        "status": "affected",
        "version": "1.2.0",
        "versionType": "firmware"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Relion protection relays - RER615",
    "vendor": "ABB",
    "versions": [
      {
        "lessThan": "2.0.3",
        "status": "affected",
        "version": "2.0.0",
        "versionType": "firmware"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Remote Monitoring and Control - REC615",
    "vendor": "ABB",
    "versions": [
      {
        "lessThan": "2.0.3",
        "status": "affected",
        "version": "1.0.0",
        "versionType": "firmware"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Merging Unit- SMU615",
    "vendor": "ABB",
    "versions": [
      {
        "lessThan": "1.0.2",
        "status": "affected",
        "version": "1.0.0",
        "versionType": "firmware"
      }
    ]
  }
]

6.2 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

9.2%

Related for CVELIST:CVE-2021-22283