PT-2022-6470 · Abb · Abb Remote Monitoring/Control+2

Published

2022-12-19

·

Updated

2023-03-13

·

CVE-2021-22283

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ABB Relion protection relays - 611 series versions 1.0.0 through 2.0.3 ABB Relion protection relays - 615 series IEC 4.0 FP1 versions 4.1.0 through 4.1.9 ABB Relion protection relays - 615 series CN 4.0 FP1 versions 4.1.0 through 4.1.8 ABB Relion protection relays - 615 series IEC 5.0 versions 5.0.0 through 5.0.12 ABB Relion protection relays - 615 series IEC 5.0 FP1 versions 5.1.0 through 5.1.20 ABB Relion protection relays - 620 series IEC/CN 2.0 versions 2.0.0 through 2.0.11 ABB Relion protection relays - 620 series IEC/CN 2.0 FP1 versions 2.1.0 through 2.1.15 ABB Relion protection relays - REX640 PCL1 versions 1.0.0 through 1.0.8 ABB Relion protection relays - REX640 PCL2 versions 1.1.0 through 1.1.4 ABB Relion protection relays - REX640 PCL3 versions 1.2.0 through 1.2.1 ABB Relion protection relays - RER615 versions 2.0.0 through 2.0.3 ABB Remote Monitoring and Control - REC615 versions 1.0.0 through 2.0.3 ABB Merging Unit- SMU615 versions 1.0.0 through 1.0.2
Description The issue is related to an improper initialization vulnerability in ABB Relion protection relays, allowing communication channel manipulation. This can be exploited by an attacker to cause a denial of service using a specially crafted MMS client.
Recommendations For ABB Relion protection relays - 611 series versions 1.0.0 through 2.0.3, update to version 2.0.3 or later. For ABB Relion protection relays - 615 series IEC 4.0 FP1 versions 4.1.0 through 4.1.9, update to version 4.1.9 or later. For ABB Relion protection relays - 615 series CN 4.0 FP1 versions 4.1.0 through 4.1.8, update to version 4.1.8 or later. For ABB Relion protection relays - 615 series IEC 5.0 versions 5.0.0 through 5.0.12, update to version 5.0.12 or later. For ABB Relion protection relays - 615 series IEC 5.0 FP1 versions 5.1.0 through 5.1.20, update to version 5.1.20 or later. For ABB Relion protection relays - 620 series IEC/CN 2.0 versions 2.0.0 through 2.0.11, update to version 2.0.11 or later. For ABB Relion protection relays - 620 series IEC/CN 2.0 FP1 versions 2.1.0 through 2.1.15, update to version 2.1.15 or later. For ABB Relion protection relays - REX640 PCL1 versions 1.0.0 through 1.0.8, update to version 1.0.8 or later. For ABB Relion protection relays - REX640 PCL2 versions 1.1.0 through 1.1.4, update to version 1.1.4 or later. For ABB Relion protection relays - REX640 PCL3 versions 1.2.0 through 1.2.1, update to version 1.2.1 or later. For ABB Relion protection relays - RER615 versions 2.0.0 through 2.0.3, update to version 2.0.3 or later. For ABB Remote Monitoring and Control - REC615 versions 1.0.0 through 2.0.3, update to version 2.0.3 or later. For ABB Merging Unit- SMU615 versions 1.0.0 through 1.0.2, update to version 1.0.2 or later.

Fix

Improper Initialization

Weakness Enumeration

Related Identifiers

BDU:2023-01637
CVE-2021-22283

Affected Products

Abb Merging Unit
Abb Relion Protection Relays
Abb Remote Monitoring/Control