Vulnerability in Relion Update Package Signature Validation by Hitachi Energy
CVE-2022-3864

4.5MEDIUM

Key Information:

Vendor

Hitachi

Vendor
CVE Published:
4 January 2024

What is CVE-2022-3864?

A vulnerability exists in the update package signature validation within Hitachi Energy's Relion platform. This flaw allows an attacker who gains security privileges to exploit the system by attempting to upload a malicious update package. When successfully exploited, the vulnerability leads to a restart of the Intelligent Electronic Device (IED), resulting in a temporary disruption of service. Although the device returns to normal operation post-restart, the potential for misuse poses serious security risks to infrastructure relying on the IEDs. Organizations should mitigate this risk by ensuring strict access control and validating update packages before installation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Relion 670/650/SAM600-IO Series Relion 670/650 series version 2.2.0 all revisions

Relion 670/650/SAM600-IO Series Relion 670/650/SAM600-IO series version 2.2.1 all revisions

Relion 670/650/SAM600-IO Series Relion 670 series version 2.2.2 all revisions

References

CVSS V3.1

Score:
4.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.