Lucene search

K
cvelistHitachi EnergyCVELIST:CVE-2023-4518
HistoryDec 01, 2023 - 2:18 p.m.

CVE-2023-4518

2023-12-0114:18:47
CWE-20
Hitachi Energy
www.cve.org
cve-2023-4518
input validation
goose messages
out of range values
ied
device reboot
attacker
exploit
vulnerability

6.5 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.0005 Low

EPSS

Percentile

17.1%

A vulnerability exists in the input validation of the GOOSE
messages where out of range values received and processed
by the IED caused a reboot of the device. In order for an
attacker to exploit the vulnerability, goose receiving blocks need
to be configured.

CNA Affected

[
  {
    "defaultStatus": "affected",
    "product": "Relion670",
    "vendor": "Hitachi Energy",
    "versions": [
      {
        "status": "affected",
        "version": " Relion 670 series version 2.2.0 all revisions"
      },
      {
        "status": "affected",
        "version": "Relion 670/650/SAM600-IO series version 2.2.1 all revisions"
      },
      {
        "status": "affected",
        "version": "elion 670 series version 2.2.2 all revisions"
      },
      {
        "status": "affected",
        "version": "Relion 670 series version 2.2.3 all revisions"
      },
      {
        "status": "affected",
        "version": "Relion 670/650 series version 2.2.4 all revisions"
      },
      {
        "status": "affected",
        "version": "Relion 670/650/SAM600-IO series version 2.2.5 all revisions"
      }
    ]
  }
]

6.5 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.0005 Low

EPSS

Percentile

17.1%

Related for CVELIST:CVE-2023-4518