CVE-2023-4518

A vulnerability exists in the input validation of the GOOSE messages where out of range values received and processed by the IED caused a reboot of the device. In order for an attacker to exploit the vulnerability, goose receiving blocks need to be configured. 
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:hitachienergy:relion_670_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hitachienergy:relion_670_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hitachienergy:relion_670_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hitachienergy:relion_670_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hitachienergy:relion_670:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:hitachienergy:relion_650_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hitachienergy:relion_650_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hitachienergy:relion_650_firmware:2.2.1:*:*:*:*:*:*:*
cpe:2.3:o:hitachienergy:relion_650_firmware:2.2.1.6:*:*:*:*:*:*:*
cpe:2.3:h:hitachienergy:relion_650:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:hitachienergy:relion_sam600-io_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hitachienergy:relion_sam600-io_firmware:2.2.1:*:*:*:*:*:*:*
cpe:2.3:o:hitachienergy:relion_sam600-io_firmware:2.2.1.6:*:*:*:*:*:*:*
cpe:2.3:h:hitachienergy:relion_sam600-io:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-12-01 15:15

Updated : 2023-12-06 18:55


NVD link : CVE-2023-4518

Mitre link : CVE-2023-4518

CVE.ORG link : CVE-2023-4518


JSON object : View

Products Affected

hitachienergy

  • relion_670_firmware
  • relion_650
  • relion_670
  • relion_sam600-io_firmware
  • relion_650_firmware
  • relion_sam600-io
CWE
CWE-1284

Improper Validation of Specified Quantity in Input

CWE-20

Improper Input Validation