5.5

CVE-2021-22283

MMS File Transfer Vulnerability impact on Distribution Automation products

Improper Initialization vulnerability in ABB Relion protection relays - 611 series, ABB Relion protection relays - 615 series IEC 4.0 FP1, ABB Relion protection relays - 615 series CN 4.0 FP1, ABB Relion protection relays - 615 series IEC 5.0, ABB Relion protection relays - 615 series IEC 5.0 FP1, ABB Relion protection relays - 620 series IEC/CN 2.0, ABB Relion protection relays - 620 series IEC/CN 2.0 FP1, ABB Relion protection relays - REX640 PCL1, ABB Relion protection relays - REX640 PCL2, ABB Relion protection relays - REX640 PCL3, ABB Relion protection relays - RER615, ABB Remote Monitoring and Control - REC615, ABB Merging Unit- SMU615 allows Communication Channel Manipulation.This issue affects Relion protection relays - 611 series: from 1.0.0 before 2.0.3; Relion protection relays - 615 series IEC 4.0 FP1: from 4.1.0 before 4.1.9; Relion protection relays - 615 series CN 4.0 FP1: from 4.1.0 before 4.1.8; Relion protection relays - 615 series IEC 5.0: from 5.0.0 before 5.0.12; Relion protection relays - 615 series IEC 5.0 FP1: from 5.1.0 before 5.1.20; Relion protection relays - 620 series IEC/CN 2.0: from 2.0.0 before 2.0.11; Relion protection relays - 620 series IEC/CN 2.0 FP1: from 2.1.0 before 2.1.15; Relion protection relays - REX640 PCL1: from 1.0.0 before 1.0.8; Relion protection relays - REX640 PCL2: from 1.1.0 before 1.1.4; Relion protection relays - REX640 PCL3: from 1.2.0 before 1.2.1; Relion protection relays - RER615: from 2.0.0 before 2.0.3; Remote Monitoring and Control - REC615: from 1.0.0 before 2.0.3; Merging Unit- SMU615: from 1.0.0 before 1.0.2.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Abb ≫ Smu615 Firmware Version < 1.0.2
   Abb ≫ Smu615 Version -
Abb ≫ Rec615 Firmware Version < 2.0.3
   Abb ≫ Rec615 Version -
Abb ≫ Rer615 Firmware Version < 2.0.3
   Abb ≫ Rer615 Version -
Abb ≫ Evd4 Firmware
   Abb ≫ Evd4 Version -
Abb ≫ Ref615r Firmware
   Abb ≫ Ref615r Version -
Abb ≫ Rex640 Pcl3 Firmware Version < 1.2.1
   Abb ≫ Rex640 Pcl3 Version -
Abb ≫ Rex640 Pcl2 Firmware Version < 1.1.4
   Abb ≫ Rex640 Pcl2 Version -
Abb ≫ Rex640 Pcl1 Firmware Version < 1.0.8
   Abb ≫ Rex640 Pcl1 Version -
Abb ≫ Rer620 Firmware
   Abb ≫ Rer620 Version -
Abb ≫ Relion 611 Firmware Version < 2.0.3
   Abb ≫ Relion 611 Version -
Abb ≫ Ref615 Iec Firmware
   Abb ≫ Ref615 Iec Version 1.0
Abb ≫ Ref615 Ansi Firmware
   Abb ≫ Ref615 Ansi Version 1.0
Abb ≫ Ref615 Iec Firmware
   Abb ≫ Ref615 Iec Version 1.1
Abb ≫ Red615 Iec Firmware
   Abb ≫ Red615 Iec Version 1.1
Abb ≫ Ref615 Ansi Firmware
   Abb ≫ Ref615 Ansi Version 1.1
Abb ≫ Relion 615 Iec Firmware
   Abb ≫ Relion 615 Iec Version 2.0
   Abb ≫ Relion 615 Iec Version 3.0
   Abb ≫ Relion 615 Iec Version 4.0 Update -
Abb ≫ Relion 615 Cn Firmware
   Abb ≫ Relion 615 Cn Version 2.0
   Abb ≫ Relion 615 Cn Version 3.0
   Abb ≫ Relion 615 Cn Version 3.1
   Abb ≫ Relion 615 Cn Version 4.0 Update -
   Abb ≫ Relion 615 Cn Version 5.0 Update fp1
Abb ≫ Relion 615 Ansi Firmware
   Abb ≫ Relion 615 Ansi Version 2.0
   Abb ≫ Relion 615 Ansi Version 4.0 Update -
   Abb ≫ Relion 615 Ansi Version 4.0 Update fp1
   Abb ≫ Relion 615 Ansi Version 4.0 Update fp2
   Abb ≫ Relion 615 Ansi Version 5.0 Update fp1
Abb ≫ Relion 615 Iec Firmware Version < 4.1.9
   Abb ≫ Relion 615 Iec Version 4.0 Update fp1
Abb ≫ Relion 615 Cn Firmware Version < 4.1.8
   Abb ≫ Relion 615 Cn Version 4.0 Update fp1
Abb ≫ Relion 615 Iec Firmware Version < 5.0.12
   Abb ≫ Relion 615 Iec Version 5.0 Update -
Abb ≫ Relion 615 Iec Firmware Version < 5.1.20
   Abb ≫ Relion 615 Iec Version 5.0 Update fp1
Abb ≫ Relion 620 Iec Firmware Version < 2.0.11
   Abb ≫ Relion 620 Iec Version 2.0 Update -
Abb ≫ Relion 620 Cn Firmware Version < 2.0.11
   Abb ≫ Relion 620 Cn Version 2.0 Update -
Abb ≫ Relion 620 Iec Firmware Version < 2.1.15
   Abb ≫ Relion 620 Iec Version 2.0 Update fp1
Abb ≫ Relion 620 Cn Firmware Version < 2.1.15
   Abb ≫ Relion 620 Cn Version 2.0 Update fp1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.067
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
cybersecurity@ch.abb.com 6.2 2.5 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-665 Improper Initialization

The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.

https://search.abb.com/library/Download.aspx?DocumentID=2NGA001147&LanguageCode=en&DocumentPartId=&Action=Launch
Vendor Advisory