CVE-2022-3864

MEDIUM

Hitachi Energy Relion 650/670/SAM600-IO Firmware - Denial of Service via Tampered Update Package

Title source: llm
STIX 2.1

Description

A vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED to restart. After restart the device is back to normal operation. An attacker could exploit the vulnerability by first gaining access to the system with security privileges and attempt to update the IED with a malicious update package. Successful exploitation of this vulnerability will cause the IED to restart, causing a temporary Denial of Service.

Scores

CVSS v3 4.5
EPSS 0.0035
EPSS Percentile 26.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-347
Status published
Products (11)
hitachienergy/relion_650_firmware 2.2.0
hitachienergy/relion_650_firmware 2.2.1
hitachienergy/relion_650_firmware 2.2.4
hitachienergy/relion_650_firmware 2.2.5
hitachienergy/relion_670_firmware 2.2.0
hitachienergy/relion_670_firmware 2.2.1
hitachienergy/relion_670_firmware 2.2.2
hitachienergy/relion_670_firmware 2.2.3
hitachienergy/relion_670_firmware 2.2.4
hitachienergy/relion_670_firmware 2.2.5
... and 1 more
Published Jan 04, 2024
Tracked Since Feb 18, 2026