Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-4518


A vulnerability exists in the input validation of the GOOSE messages where out of range values received and processed by the IED caused a reboot of the device. In order for an attacker to exploit the vulnerability, goose receiving blocks need to be configured.


Published

2023-12-01T15:15:07.860

Last Modified

2024-11-21T08:35:20.213

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-1284
  • Type: Primary
    CWE-1284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System hitachienergy relion_670_firmware < 2.2.2.6 Yes
Operating System hitachienergy relion_670_firmware < 2.2.3.7 Yes
Operating System hitachienergy relion_670_firmware < 2.2.4.4 Yes
Operating System hitachienergy relion_670_firmware < 2.2.5.6 Yes
Hardware hitachienergy relion_670 - No
Operating System hitachienergy relion_650_firmware < 2.2.4.4 Yes
Operating System hitachienergy relion_650_firmware < 2.2.5.6 Yes
Operating System hitachienergy relion_650_firmware 2.2.1 Yes
Operating System hitachienergy relion_650_firmware 2.2.1.6 Yes
Hardware hitachienergy relion_650 - No
Operating System hitachienergy relion_sam600-io_firmware < 2.2.5.6 Yes
Operating System hitachienergy relion_sam600-io_firmware 2.2.1 Yes
Operating System hitachienergy relion_sam600-io_firmware 2.2.1.6 Yes
Hardware hitachienergy relion_sam600-io - No

References