« Volver al listado

CVE-2022-3864

Estado: ModificadaMedia (4.5)—

A vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED to restart. After restart the device is back to normal operation. An attacker could exploit the vulnerability by first gaining access to the system with security privileges and attempt to update the IED with a malicious update package. Successful exploitation of this vulnerability will cause the IED to restart, causing a temporary Denial of Service.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-3864",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-3864",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-27T15:19:29.961351Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cybersecurity@hitachienergy.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.9
      }
    ]
  },
  "affected": [
    {
      "source": "cybersecurity@hitachienergy.com",
      "affectedData": [
        {
          "vendor": "Hitachi Energy",
          "product": "Relion 670/650/SAM600-IO Series",
          "versions": [
            {
              "status": "affected",
              "version": "Relion 670/650 series version 2.2.0 all revisions"
            },
            {
              "status": "affected",
              "version": "Relion 670/650/SAM600-IO series version 2.2.1 all revisions"
            },
            {
              "status": "affected",
              "version": "Relion 670 series version 2.2.2 all revisions"
            },
            {
              "status": "affected",
              "version": "Relion 670 series version 2.2.3 all revisions"
            },
            {
              "status": "affected",
              "version": "Relion 670/650 series version 2.2.4 all revisions"
            },
            {
              "status": "affected",
              "version": "Relion 670/650 series version 2.2.5 all revisions"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-01-04T10:15:11.267",
  "references": [
    {
      "url": "https://publisher.hitachienergy.com/preview?DocumentID=8DBD000146&LanguageCode=en&DocumentPartId=&Action=Launch",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cybersecurity@hitachienergy.com"
    },
    {
      "url": "https://publisher.hitachienergy.com/preview?DocumentID=8DBD000146&LanguageCode=en&DocumentPartId=&Action=Launch",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cybersecurity@hitachienergy.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-347"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-347"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\nA vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED to restart. After restart the device is back to normal operation.\nAn attacker could exploit the vulnerability by first gaining access to\nthe system with security privileges and attempt to update the IED\nwith a malicious update package. Successful exploitation of this\nvulnerability will cause the IED to restart, causing a temporary Denial of Service.\n\n"
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad en la validación de la firma del paquete de actualización de Relion. Un paquete de actualización manipulado podría provocar que el IED se reinicie. Después de reiniciar, el dispositivo vuelve a su funcionamiento normal. Un atacante podría aprovechar la vulnerabilidad obteniendo primero acceso al sistema con privilegios de seguridad e intentando actualizar el IED con un paquete de actualización malicioso. La explotación exitosa de esta vulnerabilidad hará que el IED se reinicie, lo que provocará una denegación de servicio temporal."
    }
  ],
  "lastModified": "2026-06-17T05:00:27.793",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_650_firmware:2.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EA73DFC1-3953-48DB-BF8C-545BE5B7BFAD"
            },
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_650_firmware:2.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A406AD0-38C5-4C32-AA88-AA45EE97C315"
            },
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_650_firmware:2.2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "48B56792-02FF-4E3E-B306-DC58FED37128"
            },
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_650_firmware:2.2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22E5CD7F-CD9D-4E89-BF2F-944300121D11"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:hitachienergy:relion_650:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1C658029-20F4-411A-B1FE-B4E07D590775"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_670_firmware:2.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B91C1D5F-FE14-4121-A7C8-16F08D652610"
            },
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_670_firmware:2.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A59F3E51-D3D5-4846-B8AA-6BAD4BCCCCE3"
            },
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_670_firmware:2.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E368A106-A236-4A42-8608-43F47EB4A2C4"
            },
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_670_firmware:2.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "29D2A64B-F136-49B8-9AF8-F8057F9227E0"
            },
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_670_firmware:2.2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F2F0B80-070C-4610-862B-346994BFEC51"
            },
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_670_firmware:2.2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "06064F73-366D-48C6-AACE-DCFC2F1B8E0E"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:hitachienergy:relion_670:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "ADA98332-543F-48A7-B63C-B39F679D47F0"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_sam600-io_firmware:2.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB5C50F4-CF04-4C13-868A-F7ECE49DE01B"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:hitachienergy:relion_sam600-io:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E73E9D1A-1DFE-4B7C-81F1-0809071A3DDB"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cybersecurity@hitachienergy.com"
}