PT-2021-17315 · Hitachi Abb Power Grids · Pwc600+9

Published

2021-06-14

·

Updated

2023-05-16

·

CVE-2021-27196

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Hitachi ABB Power Grids Relion 670 Series versions 1.1 through 2.2.3 Hitachi ABB Power Grids Relion 670/650 Series version 2.2.0 Hitachi ABB Power Grids Relion 670/650/SAM600-IO version 2.2.1 Hitachi ABB Power Grids Relion 650 versions 1.1 through 1.3 Hitachi ABB Power Grids REB500 versions 7.3 through 8.3 Hitachi ABB Power Grids RTU500 Series versions 7.x through 12.x Hitachi ABB Power Grids FOX615 (TEGO1) version R1D02 Hitachi ABB Power Grids MSM version 2.1.0 Hitachi ABB Power Grids GMS600 version 1.3.0 Hitachi ABB Power Grids PWC600 versions 1.0 through 1.1
Description: The issue is related to improper input validation, allowing an attacker with access to the IEC 61850 network and knowledge of how to reproduce the attack to force the device to reboot. This renders the device inoperable for approximately 60 seconds. The vulnerability affects products with IEC 61850 interfaces.
Recommendations: For Hitachi ABB Power Grids Relion 670 Series versions 1.1 through 2.2.3, update to a version after 2.2.3. For Hitachi ABB Power Grids Relion 670/650 Series version 2.2.0, update to a version after 2.2.0. For Hitachi ABB Power Grids Relion 670/650/SAM600-IO version 2.2.1, update to a version after 2.2.1. For Hitachi ABB Power Grids Relion 650 versions 1.1 through 1.3, update to a version after 1.3. For Hitachi ABB Power Grids REB500 versions 7.3 through 8.3, update to a version after 8.3. For Hitachi ABB Power Grids RTU500 Series versions 7.x through 12.x, update to a version after 12.x. For Hitachi ABB Power Grids FOX615 (TEGO1) version R1D02, update to a version after R1D02. For Hitachi ABB Power Grids MSM version 2.1.0, update to a version after 2.1.0. For Hitachi ABB Power Grids GMS600 version 1.3.0, update to a version after 1.3.0. For Hitachi ABB Power Grids PWC600 versions 1.0 through 1.1, update to a version after 1.1.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2021-27196

Affected Products

Fox615
Gms600
Msm
Pwc600
Reb500
Rtu500 Series
Relion 650
Relion 670 Series
Relion 670/650 Series
Relion 670/650/Sam600-Io