CVE-2022-3864

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/01/2024
Last modified:
10/01/2024

Description

<br /> A vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED to restart. After restart the device is back to normal operation.<br /> An attacker could exploit the vulnerability by first gaining access to<br /> the system with security privileges and attempt to update the IED<br /> with a malicious update package. Successful exploitation of this<br /> vulnerability will cause the IED to restart, causing a temporary Denial of Service.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hitachienergy:relion_650_firmware:2.2.0:*:*:*:*:*:*:*
cpe:2.3:o:hitachienergy:relion_650_firmware:2.2.1:*:*:*:*:*:*:*
cpe:2.3:o:hitachienergy:relion_650_firmware:2.2.4:*:*:*:*:*:*:*
cpe:2.3:o:hitachienergy:relion_650_firmware:2.2.5:*:*:*:*:*:*:*
cpe:2.3:h:hitachienergy:relion_650:-:*:*:*:*:*:*:*
cpe:2.3:o:hitachienergy:relion_670_firmware:2.2.0:*:*:*:*:*:*:*
cpe:2.3:o:hitachienergy:relion_670_firmware:2.2.1:*:*:*:*:*:*:*
cpe:2.3:o:hitachienergy:relion_670_firmware:2.2.2:*:*:*:*:*:*:*
cpe:2.3:o:hitachienergy:relion_670_firmware:2.2.3:*:*:*:*:*:*:*
cpe:2.3:o:hitachienergy:relion_670_firmware:2.2.4:*:*:*:*:*:*:*
cpe:2.3:o:hitachienergy:relion_670_firmware:2.2.5:*:*:*:*:*:*:*
cpe:2.3:h:hitachienergy:relion_670:-:*:*:*:*:*:*:*
cpe:2.3:o:hitachienergy:relion_sam600-io_firmware:2.2.1:*:*:*:*:*:*:*
cpe:2.3:h:hitachienergy:relion_sam600-io:-:*:*:*:*:*:*:*