« Volver al listado

CVE-2014-9196

Estado: ModificadaAlta (9.3)—

Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and IdeaPLUS relays generates TCP initial sequence number (ISN) values linearly, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-9196",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Secondary",
        "source": "ics-cert@hq.dhs.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.6,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "HIGH",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 4.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "ics-cert@hq.dhs.gov",
      "affectedData": [
        {
          "vendor": "Eaton’s Cooper Power Systems",
          "product": "Series Form 6",
          "versions": [
            {
              "status": "affected",
              "version": "Pro View 4.0",
              "versionType": "custom",
              "lessThanOrEqual": "Pro View 5.0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Eaton’s Cooper Power Systems",
          "product": "Idea/IdeaPLUS relays",
          "versions": [
            {
              "status": "affected",
              "version": "Pro View 4.0",
              "versionType": "custom",
              "lessThanOrEqual": "Pro View 5.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2015-07-20T01:59:01.113",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/75936",
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-15-006-01",
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://www.eaton.com/cybersecurity",
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "http://www.securityfocus.com/bid/75936",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://ics-cert.us-cert.gov/advisories/ICSA-15-006-01",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ics-cert@hq.dhs.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-342"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-254"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and IdeaPLUS relays generates TCP initial sequence number (ISN) values linearly, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value."
    },
    {
      "lang": "es",
      "value": "'ulnerabilidad en Eaton Cooper Power Systems ProView en las versiones 4.0 y 5.0 anterior a la 5.0 11 Form 6 controles e Idea e IdeaPLUS relay genera un número TCP inicial de secuencia (ISN) de valores lineales, lo que hace que sea más fácil para los atacantes remotos falsificar las sesiones TCP al predecir un valor ISN."
    }
  ],
  "lastModified": "2026-06-17T00:17:54.553",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:eaton:proview:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "09E9D87B-D0F2-48DD-97F1-9CB5D7B319E8"
            },
            {
              "criteria": "cpe:2.3:a:eaton:proview:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BD294C06-DCE8-45B1-A59E-E45CB50CA089"
            },
            {
              "criteria": "cpe:2.3:a:eaton:proview:5.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "91712733-5783-4B9A-8BD8-62A32229BC03"
            },
            {
              "criteria": "cpe:2.3:a:eaton:proview:5.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FDCAC23C-22B9-4862-A967-453812EEAA3F"
            },
            {
              "criteria": "cpe:2.3:a:eaton:proview:5.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "91DEAC57-6765-4470-963E-E9EC364657AF"
            },
            {
              "criteria": "cpe:2.3:a:eaton:proview:5.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "955879A7-9F8F-47F2-B8F0-7D62AB69261D"
            },
            {
              "criteria": "cpe:2.3:a:eaton:proview:5.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ADF48CE1-EC38-4F11-82D1-514C993AF1FA"
            },
            {
              "criteria": "cpe:2.3:a:eaton:proview:5.0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9705072-55EE-46E6-B124-8C7A20D6DC03"
            },
            {
              "criteria": "cpe:2.3:a:eaton:proview:5.0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "04909702-7055-4822-BAB8-139EBF4E409C"
            },
            {
              "criteria": "cpe:2.3:a:eaton:proview:5.0.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7484B7D1-D109-4E5E-B26F-4FEB88E68EB1"
            },
            {
              "criteria": "cpe:2.3:a:eaton:proview:5.0.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E64750AD-BAA4-4837-BA51-87019A585C91"
            },
            {
              "criteria": "cpe:2.3:a:eaton:proview:5.0.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5BFA9727-CBCA-45BC-B4BA-0B5730C05450"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "ics-cert@hq.dhs.gov"
}