4.5
CVE-2022-3864
- EPSS 0.05%
- Veröffentlicht 04.01.2024 10:15:11
- Zuletzt bearbeitet 21.11.2024 07:20:23
- Quelle cybersecurity@hitachienergy.co
- Teams Watchlist Login
- Unerledigt Login
A vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED to restart. After restart the device is back to normal operation. An attacker could exploit the vulnerability by first gaining access to the system with security privileges and attempt to update the IED with a malicious update package. Successful exploitation of this vulnerability will cause the IED to restart, causing a temporary Denial of Service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hitachienergy ≫ Relion 650 Firmware Version2.2.0
Hitachienergy ≫ Relion 650 Firmware Version2.2.1
Hitachienergy ≫ Relion 650 Firmware Version2.2.4
Hitachienergy ≫ Relion 650 Firmware Version2.2.5
Hitachienergy ≫ Relion 670 Firmware Version2.2.0
Hitachienergy ≫ Relion 670 Firmware Version2.2.1
Hitachienergy ≫ Relion 670 Firmware Version2.2.2
Hitachienergy ≫ Relion 670 Firmware Version2.2.3
Hitachienergy ≫ Relion 670 Firmware Version2.2.4
Hitachienergy ≫ Relion 670 Firmware Version2.2.5
Hitachienergy ≫ Relion Sam600-io Firmware Version2.2.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.137 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.5 | 0.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H
|
cybersecurity@hitachienergy.com | 4.5 | 0.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.