« Volver al listado

CVE-2023-4518

Estado: ModificadaAlta (7.5)—

A vulnerability exists in the input validation of the GOOSE messages where out of range values received and processed by the IED caused a reboot of the device. In order for an attacker to exploit the vulnerability, goose receiving blocks need to be configured.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-4518",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cybersecurity@hitachienergy.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cybersecurity@hitachienergy.com",
      "affectedData": [
        {
          "vendor": "Hitachi Energy",
          "product": "Relion670",
          "versions": [
            {
              "status": "affected",
              "version": "Relion 670 series version 2.2.0 all revisions"
            },
            {
              "status": "affected",
              "version": "Relion 670/650/SAM600-IO series version 2.2.1 all revisions"
            },
            {
              "status": "affected",
              "version": "elion 670 series version 2.2.2 all revisions"
            },
            {
              "status": "affected",
              "version": "Relion 670 series version 2.2.3 all revisions"
            },
            {
              "status": "affected",
              "version": "Relion 670/650 series version 2.2.4 all revisions"
            },
            {
              "status": "affected",
              "version": "Relion 670/650/SAM600-IO series version 2.2.5 all revisions"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2023-12-01T15:15:07.860",
  "references": [
    {
      "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000170&languageCode=en&Preview=true",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cybersecurity@hitachienergy.com"
    },
    {
      "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000170&languageCode=en&Preview=true",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cybersecurity@hitachienergy.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1284"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability exists in the input validation of the GOOSE \nmessages where out of range values received and processed \nby the IED caused a reboot of the device. In order for an \nattacker to exploit the vulnerability, goose receiving blocks need \nto be configured."
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad en la validación de entrada de los mensajes GOOSE donde los valores fuera de rango recibidos y procesados por el IED provocaron un reinicio del dispositivo. Para que un atacante aproveche la vulnerabilidad, es necesario configurar los bloques receptores de ganso."
    }
  ],
  "lastModified": "2026-06-17T06:38:00.413",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_670_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1C4B7DA8-BA72-48E5-9E21-33FB1881E952",
              "versionEndExcluding": "2.2.2.6",
              "versionStartIncluding": "2.2.0"
            },
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_670_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4949214C-03DE-489E-80E3-7DC4EFED7ACA",
              "versionEndExcluding": "2.2.3.7",
              "versionStartIncluding": "2.2.3"
            },
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_670_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "53D9E635-5BDA-4383-9FE5-4AFA4148A5E3",
              "versionEndExcluding": "2.2.4.4",
              "versionStartIncluding": "2.2.4"
            },
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_670_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "64A83135-6909-4838-9429-1046CA824723",
              "versionEndExcluding": "2.2.5.6",
              "versionStartIncluding": "2.2.5"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:hitachienergy:relion_670:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "ADA98332-543F-48A7-B63C-B39F679D47F0"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_650_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "612B2549-82F9-4B7F-BDBD-95A562BF1EAE",
              "versionEndExcluding": "2.2.4.4",
              "versionStartIncluding": "2.2.4"
            },
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_650_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC7C5065-1CEC-44DC-BF01-16FC02390583",
              "versionEndExcluding": "2.2.5.6",
              "versionStartIncluding": "2.2.5"
            },
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_650_firmware:2.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A406AD0-38C5-4C32-AA88-AA45EE97C315"
            },
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_650_firmware:2.2.1.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A74BD43-D925-483C-98F7-5F5C32D3B6F7"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:hitachienergy:relion_650:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1C658029-20F4-411A-B1FE-B4E07D590775"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_sam600-io_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "264C95EE-756F-434E-9FA1-DC7878CEEF61",
              "versionEndExcluding": "2.2.5.6",
              "versionStartIncluding": "2.2.5"
            },
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_sam600-io_firmware:2.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB5C50F4-CF04-4C13-868A-F7ECE49DE01B"
            },
            {
              "criteria": "cpe:2.3:o:hitachienergy:relion_sam600-io_firmware:2.2.1.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7025C2A4-698E-408C-9567-8759B638AB90"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:hitachienergy:relion_sam600-io:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E73E9D1A-1DFE-4B7C-81F1-0809071A3DDB"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cybersecurity@hitachienergy.com"
}