// For flags

CVE-2022-3864

 

Severity Score

4.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

A vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED to restart. After restart the device is back to normal operation.
An attacker could exploit the vulnerability by first gaining access to
the system with security privileges and attempt to update the IED
with a malicious update package. Successful exploitation of this
vulnerability will cause the IED to restart, causing a temporary Denial of Service.

Existe una vulnerabilidad en la validación de la firma del paquete de actualización de Relion. Un paquete de actualización manipulado podría provocar que el IED se reinicie. Después de reiniciar, el dispositivo vuelve a su funcionamiento normal. Un atacante podría aprovechar la vulnerabilidad obteniendo primero acceso al sistema con privilegios de seguridad e intentando actualizar el IED con un paquete de actualización malicioso. La explotación exitosa de esta vulnerabilidad hará que el IED se reinicie, lo que provocará una denegación de servicio temporal.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2022-11-04 CVE Reserved
  • 2024-01-04 CVE Published
  • 2024-01-11 EPSS Updated
  • 2024-08-27 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-347: Improper Verification of Cryptographic Signature
CAPEC
  • CAPEC-186: Malicious Software Update
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hitachienergy
Search vendor "Hitachienergy"
Relion 650 Firmware
Search vendor "Hitachienergy" for product "Relion 650 Firmware"
2.2.0
Search vendor "Hitachienergy" for product "Relion 650 Firmware" and version "2.2.0"
-
Affected
in Hitachienergy
Search vendor "Hitachienergy"
Relion 650
Search vendor "Hitachienergy" for product "Relion 650"
--
Safe
Hitachienergy
Search vendor "Hitachienergy"
Relion 650 Firmware
Search vendor "Hitachienergy" for product "Relion 650 Firmware"
2.2.1
Search vendor "Hitachienergy" for product "Relion 650 Firmware" and version "2.2.1"
-
Affected
in Hitachienergy
Search vendor "Hitachienergy"
Relion 650
Search vendor "Hitachienergy" for product "Relion 650"
--
Safe
Hitachienergy
Search vendor "Hitachienergy"
Relion 650 Firmware
Search vendor "Hitachienergy" for product "Relion 650 Firmware"
2.2.4
Search vendor "Hitachienergy" for product "Relion 650 Firmware" and version "2.2.4"
-
Affected
in Hitachienergy
Search vendor "Hitachienergy"
Relion 650
Search vendor "Hitachienergy" for product "Relion 650"
--
Safe
Hitachienergy
Search vendor "Hitachienergy"
Relion 650 Firmware
Search vendor "Hitachienergy" for product "Relion 650 Firmware"
2.2.5
Search vendor "Hitachienergy" for product "Relion 650 Firmware" and version "2.2.5"
-
Affected
in Hitachienergy
Search vendor "Hitachienergy"
Relion 650
Search vendor "Hitachienergy" for product "Relion 650"
--
Safe
Hitachienergy
Search vendor "Hitachienergy"
Relion 670 Firmware
Search vendor "Hitachienergy" for product "Relion 670 Firmware"
2.2.0
Search vendor "Hitachienergy" for product "Relion 670 Firmware" and version "2.2.0"
-
Affected
in Hitachienergy
Search vendor "Hitachienergy"
Relion 670
Search vendor "Hitachienergy" for product "Relion 670"
--
Safe
Hitachienergy
Search vendor "Hitachienergy"
Relion 670 Firmware
Search vendor "Hitachienergy" for product "Relion 670 Firmware"
2.2.1
Search vendor "Hitachienergy" for product "Relion 670 Firmware" and version "2.2.1"
-
Affected
in Hitachienergy
Search vendor "Hitachienergy"
Relion 670
Search vendor "Hitachienergy" for product "Relion 670"
--
Safe
Hitachienergy
Search vendor "Hitachienergy"
Relion 670 Firmware
Search vendor "Hitachienergy" for product "Relion 670 Firmware"
2.2.2
Search vendor "Hitachienergy" for product "Relion 670 Firmware" and version "2.2.2"
-
Affected
in Hitachienergy
Search vendor "Hitachienergy"
Relion 670
Search vendor "Hitachienergy" for product "Relion 670"
--
Safe
Hitachienergy
Search vendor "Hitachienergy"
Relion 670 Firmware
Search vendor "Hitachienergy" for product "Relion 670 Firmware"
2.2.3
Search vendor "Hitachienergy" for product "Relion 670 Firmware" and version "2.2.3"
-
Affected
in Hitachienergy
Search vendor "Hitachienergy"
Relion 670
Search vendor "Hitachienergy" for product "Relion 670"
--
Safe
Hitachienergy
Search vendor "Hitachienergy"
Relion 670 Firmware
Search vendor "Hitachienergy" for product "Relion 670 Firmware"
2.2.4
Search vendor "Hitachienergy" for product "Relion 670 Firmware" and version "2.2.4"
-
Affected
in Hitachienergy
Search vendor "Hitachienergy"
Relion 670
Search vendor "Hitachienergy" for product "Relion 670"
--
Safe
Hitachienergy
Search vendor "Hitachienergy"
Relion 670 Firmware
Search vendor "Hitachienergy" for product "Relion 670 Firmware"
2.2.5
Search vendor "Hitachienergy" for product "Relion 670 Firmware" and version "2.2.5"
-
Affected
in Hitachienergy
Search vendor "Hitachienergy"
Relion 670
Search vendor "Hitachienergy" for product "Relion 670"
--
Safe
Hitachienergy
Search vendor "Hitachienergy"
Relion Sam600-io Firmware
Search vendor "Hitachienergy" for product "Relion Sam600-io Firmware"
2.2.1
Search vendor "Hitachienergy" for product "Relion Sam600-io Firmware" and version "2.2.1"
-
Affected
in Hitachienergy
Search vendor "Hitachienergy"
Relion Sam600-io
Search vendor "Hitachienergy" for product "Relion Sam600-io"
--
Safe