PT-2022-6470 · Abb · Abb Remote Monitoring/Control+2
Published
2022-12-19
·
Updated
2023-03-13
·
CVE-2021-22283
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ABB Relion protection relays - 611 series versions 1.0.0 through 2.0.3
ABB Relion protection relays - 615 series IEC 4.0 FP1 versions 4.1.0 through 4.1.9
ABB Relion protection relays - 615 series CN 4.0 FP1 versions 4.1.0 through 4.1.8
ABB Relion protection relays - 615 series IEC 5.0 versions 5.0.0 through 5.0.12
ABB Relion protection relays - 615 series IEC 5.0 FP1 versions 5.1.0 through 5.1.20
ABB Relion protection relays - 620 series IEC/CN 2.0 versions 2.0.0 through 2.0.11
ABB Relion protection relays - 620 series IEC/CN 2.0 FP1 versions 2.1.0 through 2.1.15
ABB Relion protection relays - REX640 PCL1 versions 1.0.0 through 1.0.8
ABB Relion protection relays - REX640 PCL2 versions 1.1.0 through 1.1.4
ABB Relion protection relays - REX640 PCL3 versions 1.2.0 through 1.2.1
ABB Relion protection relays - RER615 versions 2.0.0 through 2.0.3
ABB Remote Monitoring and Control - REC615 versions 1.0.0 through 2.0.3
ABB Merging Unit- SMU615 versions 1.0.0 through 1.0.2
Description
The issue is related to an improper initialization vulnerability in ABB Relion protection relays, allowing communication channel manipulation. This can be exploited by an attacker to cause a denial of service using a specially crafted MMS client.
Recommendations
For ABB Relion protection relays - 611 series versions 1.0.0 through 2.0.3, update to version 2.0.3 or later.
For ABB Relion protection relays - 615 series IEC 4.0 FP1 versions 4.1.0 through 4.1.9, update to version 4.1.9 or later.
For ABB Relion protection relays - 615 series CN 4.0 FP1 versions 4.1.0 through 4.1.8, update to version 4.1.8 or later.
For ABB Relion protection relays - 615 series IEC 5.0 versions 5.0.0 through 5.0.12, update to version 5.0.12 or later.
For ABB Relion protection relays - 615 series IEC 5.0 FP1 versions 5.1.0 through 5.1.20, update to version 5.1.20 or later.
For ABB Relion protection relays - 620 series IEC/CN 2.0 versions 2.0.0 through 2.0.11, update to version 2.0.11 or later.
For ABB Relion protection relays - 620 series IEC/CN 2.0 FP1 versions 2.1.0 through 2.1.15, update to version 2.1.15 or later.
For ABB Relion protection relays - REX640 PCL1 versions 1.0.0 through 1.0.8, update to version 1.0.8 or later.
For ABB Relion protection relays - REX640 PCL2 versions 1.1.0 through 1.1.4, update to version 1.1.4 or later.
For ABB Relion protection relays - REX640 PCL3 versions 1.2.0 through 1.2.1, update to version 1.2.1 or later.
For ABB Relion protection relays - RER615 versions 2.0.0 through 2.0.3, update to version 2.0.3 or later.
For ABB Remote Monitoring and Control - REC615 versions 1.0.0 through 2.0.3, update to version 2.0.3 or later.
For ABB Merging Unit- SMU615 versions 1.0.0 through 1.0.2, update to version 1.0.2 or later.
Fix
Improper Initialization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Abb Merging Unit
Abb Relion Protection Relays
Abb Remote Monitoring/Control