CVE-2014-9196
Estado: ModificadaAlta (9.3)—
Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and IdeaPLUS relays generates TCP initial sequence number (ISN) values linearly, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
- Puntuación base: 9.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.25%
- Percentil entre todas las CVEs puntuadas: 82
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-342
- CWE-254
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2014-9196",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.6,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "HIGH",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 4.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "Eaton’s Cooper Power Systems",
"product": "Series Form 6",
"versions": [
{
"status": "affected",
"version": "Pro View 4.0",
"versionType": "custom",
"lessThanOrEqual": "Pro View 5.0"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Eaton’s Cooper Power Systems",
"product": "Idea/IdeaPLUS relays",
"versions": [
{
"status": "affected",
"version": "Pro View 4.0",
"versionType": "custom",
"lessThanOrEqual": "Pro View 5.0"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2015-07-20T01:59:01.113",
"references": [
{
"url": "http://www.securityfocus.com/bid/75936",
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-15-006-01",
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://www.eaton.com/cybersecurity",
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "http://www.securityfocus.com/bid/75936",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-15-006-01",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"description": [
{
"lang": "en",
"value": "CWE-342"
}
]
},
{
"type": "Secondary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-254"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and IdeaPLUS relays generates TCP initial sequence number (ISN) values linearly, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value."
},
{
"lang": "es",
"value": "'ulnerabilidad en Eaton Cooper Power Systems ProView en las versiones 4.0 y 5.0 anterior a la 5.0 11 Form 6 controles e Idea e IdeaPLUS relay genera un número TCP inicial de secuencia (ISN) de valores lineales, lo que hace que sea más fácil para los atacantes remotos falsificar las sesiones TCP al predecir un valor ISN."
}
],
"lastModified": "2026-06-17T00:17:54.553",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:eaton:proview:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "09E9D87B-D0F2-48DD-97F1-9CB5D7B319E8"
},
{
"criteria": "cpe:2.3:a:eaton:proview:5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BD294C06-DCE8-45B1-A59E-E45CB50CA089"
},
{
"criteria": "cpe:2.3:a:eaton:proview:5.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "91712733-5783-4B9A-8BD8-62A32229BC03"
},
{
"criteria": "cpe:2.3:a:eaton:proview:5.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FDCAC23C-22B9-4862-A967-453812EEAA3F"
},
{
"criteria": "cpe:2.3:a:eaton:proview:5.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "91DEAC57-6765-4470-963E-E9EC364657AF"
},
{
"criteria": "cpe:2.3:a:eaton:proview:5.0.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "955879A7-9F8F-47F2-B8F0-7D62AB69261D"
},
{
"criteria": "cpe:2.3:a:eaton:proview:5.0.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ADF48CE1-EC38-4F11-82D1-514C993AF1FA"
},
{
"criteria": "cpe:2.3:a:eaton:proview:5.0.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B9705072-55EE-46E6-B124-8C7A20D6DC03"
},
{
"criteria": "cpe:2.3:a:eaton:proview:5.0.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "04909702-7055-4822-BAB8-139EBF4E409C"
},
{
"criteria": "cpe:2.3:a:eaton:proview:5.0.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7484B7D1-D109-4E5E-B26F-4FEB88E68EB1"
},
{
"criteria": "cpe:2.3:a:eaton:proview:5.0.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E64750AD-BAA4-4837-BA51-87019A585C91"
},
{
"criteria": "cpe:2.3:a:eaton:proview:5.0.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5BFA9727-CBCA-45BC-B4BA-0B5730C05450"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}