4.5

CVE-2022-3864

A vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED to restart. After restart the device is back to normal operation.
An attacker could exploit the vulnerability by first gaining access to
the system with security privileges and attempt to update the IED
with a malicious update package. Successful exploitation of this
vulnerability will cause the IED to restart, causing a temporary Denial of Service.

Data is provided by the National Vulnerability Database (NVD)
HitachienergyRelion 650 Firmware Version2.2.0
   HitachienergyRelion 650 Version-
HitachienergyRelion 650 Firmware Version2.2.1
   HitachienergyRelion 650 Version-
HitachienergyRelion 650 Firmware Version2.2.4
   HitachienergyRelion 650 Version-
HitachienergyRelion 650 Firmware Version2.2.5
   HitachienergyRelion 650 Version-
HitachienergyRelion 670 Firmware Version2.2.0
   HitachienergyRelion 670 Version-
HitachienergyRelion 670 Firmware Version2.2.1
   HitachienergyRelion 670 Version-
HitachienergyRelion 670 Firmware Version2.2.2
   HitachienergyRelion 670 Version-
HitachienergyRelion 670 Firmware Version2.2.3
   HitachienergyRelion 670 Version-
HitachienergyRelion 670 Firmware Version2.2.4
   HitachienergyRelion 670 Version-
HitachienergyRelion 670 Firmware Version2.2.5
   HitachienergyRelion 670 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.137
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.5 0.9 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H
cybersecurity@hitachienergy.com 4.5 0.9 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H
CWE-347 Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.