9.3

CVE-2014-9196

Eaton’s Cooper Power Series Form 6 Control and Idea/IdeaPlus Relays with Ethernet

Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and IdeaPLUS relays generates TCP initial sequence number (ISN) values linearly, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EatonProview Version4.0
EatonProview Version5.0
EatonProview Version5.0.1
EatonProview Version5.0.2
EatonProview Version5.0.3
EatonProview Version5.0.4
EatonProview Version5.0.5
EatonProview Version5.0.6
EatonProview Version5.0.7
EatonProview Version5.0.8
EatonProview Version5.0.9
EatonProview Version5.0.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.25% 0.806
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
ics-cert@hq.dhs.gov 7.6 4.9 10
AV:N/AC:H/Au:N/C:C/I:C/A:C
CWE-342 Predictable Exact Value from Previous Values

An exact value or random number can be precisely predicted by observing previous values.

http://www.securityfocus.com/bid/75936
https://ics-cert.us-cert.gov/advisories/ICSA-15-006-01
Third Party Advisory
US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-15-006-01
https://www.eaton.com/cybersecurity