{"id": "CVE-2021-22283", "metrics": {"cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 5.5, "attackVector": "LOCAL", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "NONE"}, "impactScore": 3.6, "exploitabilityScore": 1.8}, {"type": "Secondary", "source": "cybersecurity@ch.abb.com", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 6.2, "attackVector": "LOCAL", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "NONE"}, "impactScore": 3.6, "exploitabilityScore": 2.5}]}, "published": "2023-02-28T05:15:12.260", "references": [{"url": "https://search.abb.com/library/Download.aspx?DocumentID=2NGA001147&LanguageCode=en&DocumentPartId=&Action=Launch", "tags": ["Vendor Advisory"], "source": "cybersecurity@ch.abb.com"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-665"}]}, {"type": "Secondary", "source": "cybersecurity@ch.abb.com", "description": [{"lang": "en", "value": "CWE-665"}]}], "descriptions": [{"lang": "en", "value": "Improper Initialization vulnerability in ABB Relion protection relays - 611 series, ABB Relion protection relays - 615 series IEC 4.0 FP1, ABB Relion protection relays - 615 series CN 4.0 FP1, ABB Relion protection relays - 615 series IEC 5.0, ABB Relion protection relays - 615 series IEC 5.0 FP1, ABB Relion protection relays - 620 series IEC/CN 2.0, ABB Relion protection relays - 620 series IEC/CN 2.0 FP1, ABB Relion protection relays - REX640 PCL1, ABB Relion protection relays - REX640 PCL2, ABB Relion protection relays - REX640 PCL3, ABB Relion protection relays - RER615, ABB Remote Monitoring and Control - REC615, ABB Merging Unit- SMU615 allows Communication Channel Manipulation.This issue affects Relion protection relays - 611 series: from 1.0.0 before 2.0.3; Relion protection relays - 615 series IEC 4.0 FP1: from 4.1.0 before 4.1.9; Relion protection relays - 615 series CN 4.0 FP1: from 4.1.0 before 4.1.8; Relion protection relays - 615 series IEC 5.0: from 5.0.0 before 5.0.12; Relion protection relays - 615 series IEC 5.0 FP1: from 5.1.0 before 5.1.20; Relion protection relays - 620 series IEC/CN 2.0: from 2.0.0 before 2.0.11; Relion protection relays - 620 series IEC/CN 2.0 FP1: from 2.1.0 before 2.1.15; Relion protection relays - REX640 PCL1: from 1.0.0 before 1.0.8; Relion protection relays - REX640 PCL2: from 1.1.0 before 1.1.4; Relion protection relays - REX640 PCL3: from 1.2.0 before 1.2.1; Relion protection relays - RER615: from 2.0.0 before 2.0.3; Remote Monitoring and Control - REC615: from 1.0.0 before 2.0.3; Merging Unit- SMU615: from 1.0.0 before 1.0.2.\n\n"}], "lastModified": "2023-11-07T03:30:11.330", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:smu615_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C01EB90B-8C81-4745-91C2-62747B185AE3", "versionEndExcluding": "1.0.2"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:smu615:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F24FC432-A799-44A1-9D7C-BF02203655C5"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:rec615_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AEDB4A6F-2E61-4962-A3D5-350070435A3B", "versionEndExcluding": "2.0.3"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:rec615:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D5A61686-5740-48D4-AF7C-34F3323F4171"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:rer615_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8DBD6846-1876-4EB7-B450-23689D08D05C", "versionEndExcluding": "2.0.3"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:rer615:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F4FB1663-BA8D-4EDA-85D3-37FF05718FB7"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:evd4_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D151411F-BBA1-4CC1-A898-7922CE9C734C"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:evd4:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "EEA5D2E2-AA96-4C81-8979-744778F19CC0"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:ref615r_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5BB52A0A-144A-4701-A169-0DE203AF3733"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:ref615r:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9C1A2F33-73B8-488B-A88C-3546CA9FB51D"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:rex640_pcl3_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E3973E21-DF2C-47BB-8C03-6FA027018873", "versionEndExcluding": "1.2.1"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:rex640_pcl3:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "90916E18-27EF-46C7-979B-19D53F901CC7"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:rex640_pcl2_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FBE1B4D1-27C7-4EA9-ADA5-A7FE42E04FF6", "versionEndExcluding": "1.1.4"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:rex640_pcl2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "AE78102B-C672-4969-8B82-FE5ACE2FFC71"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:rex640_pcl1_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AAA125ED-192D-4E4E-A4FC-FB7EF387FD90", "versionEndExcluding": "1.0.8"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:rex640_pcl1:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9256FAAB-77CF-482C-B736-FC99885C89D7"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:rer620_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F8506D82-076A-4B42-AF41-CECE5B9F42A1"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:rer620:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "A0CDB660-57FB-4B12-B457-D32A20CB054D"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:relion_611_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F1D7EA08-4326-47EA-8045-135263708315", "versionEndExcluding": "2.0.3"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:relion_611:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7D0BD760-FCEA-4620-A8D9-407C4670BDA0"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:ref615_iec_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B53D526E-2EE7-4D50-B6AE-43A2E5F51902"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:ref615_iec:1.0:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9A52B165-B93A-4CD5-85F7-8DC085B8BF8D"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:ref615_ansi_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6B0493F4-7619-4D98-9D15-069ECAF34EA2"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:ref615_ansi:1.0:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "27CE34F9-8441-4327-A7CF-BC9ED6C2838C"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:ref615_iec_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B53D526E-2EE7-4D50-B6AE-43A2E5F51902"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:ref615_iec:1.1:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5C694E31-330C-41B1-A080-278A1C3111A2"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:red615_iec_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D1375F21-B685-4CC8-B781-73D68B07DC5B"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:red615_iec:1.1:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B694B186-62A0-4235-97EB-EF4A9F02F185"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:ref615_ansi_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6B0493F4-7619-4D98-9D15-069ECAF34EA2"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:ref615_ansi:1.1:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "A250B053-1FD7-44F1-8622-C6FDFF4DE575"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:relion_615_iec_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "81982E5D-C2B7-40E5-B4B1-20E05558C183"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:relion_615_iec:2.0:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E98E9975-0978-4632-9202-A036A2D66C7F"}, {"criteria": "cpe:2.3:h:abb:relion_615_iec:3.0:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0954C681-0897-441F-AD78-2B1FBC6EC208"}, {"criteria": "cpe:2.3:h:abb:relion_615_iec:4.0:-:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D9C4BDD6-3EE7-4DC9-97C7-8F7F04DD80F8"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:relion_615_cn_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "50CB9495-DBBC-4B36-AF67-6D5E1CD4CE76"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:relion_615_cn:2.0:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D2773068-653B-4F02-8CB8-5CA4CF7D6574"}, {"criteria": "cpe:2.3:h:abb:relion_615_cn:3.0:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "66B405A7-E16B-48E0-AFC9-36A6AB21451D"}, {"criteria": "cpe:2.3:h:abb:relion_615_cn:3.1:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "334CAC56-FBBC-45D4-9161-A53197CB30C2"}, {"criteria": "cpe:2.3:h:abb:relion_615_cn:4.0:-:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0B5B5511-A4EF-4814-BD67-F5A2F445B111"}, {"criteria": "cpe:2.3:h:abb:relion_615_cn:5.0:fp1:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "431FDF0D-6734-40C0-AFA5-A5513B7324E6"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:relion_615_ansi_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "78236AA2-3560-402B-B2FC-13070B805609"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:relion_615_ansi:2.0:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "591DB01E-3610-4AD2-A5F9-D8A061B597A5"}, {"criteria": "cpe:2.3:h:abb:relion_615_ansi:4.0:-:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "63988EAE-73F9-4362-8B38-EDC3B1207F0F"}, {"criteria": "cpe:2.3:h:abb:relion_615_ansi:4.0:fp1:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "05EF9495-C9B5-40C6-B648-C85B35373023"}, {"criteria": "cpe:2.3:h:abb:relion_615_ansi:4.0:fp2:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0208F75C-011B-4A15-AD1B-8DD1550B3077"}, {"criteria": "cpe:2.3:h:abb:relion_615_ansi:5.0:fp1:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8B25AD70-B3B4-45A7-B4B6-E072BA0A336A"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:relion_615_iec_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C79758CF-9F3B-4A79-A8D4-3D17D5D85497", "versionEndExcluding": "4.1.9"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:relion_615_iec:4.0:fp1:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "A6E38E09-2B98-4B3A-BFC0-391DE22ABDE9"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:relion_615_cn_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "79918D6E-7694-43B2-B474-649174A00054", "versionEndExcluding": "4.1.8"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:relion_615_cn:4.0:fp1:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "412F7432-5049-4DB0-8009-6783A3821F1F"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:relion_615_iec_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3FE9A6FF-BBFD-48D6-B9D2-3AD244221C20", "versionEndExcluding": "5.0.12"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:relion_615_iec:5.0:-:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "DE999A72-CEED-4235-B68F-590CF1128268"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:relion_615_iec_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "47DB1FAF-07D7-44FD-8368-BB29FF0DB4AD", "versionEndExcluding": "5.1.20"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:relion_615_iec:5.0:fp1:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "50330FD9-AA32-439B-9E06-7228A7338F46"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:relion_620_iec_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F5E4CADD-7849-40B5-9DC6-8B0571A5B16E", "versionEndExcluding": "2.0.11"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:relion_620_iec:2.0:-:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "91122A2B-236D-4D36-93BD-93A6C2DB0263"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:relion_620_cn_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C7230BC1-056F-4E13-AA11-8B19AC404B71", "versionEndExcluding": "2.0.11"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:relion_620_cn:2.0:-:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "281A30D2-94DA-4D19-AAA7-30061BD94443"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:relion_620_ansi_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AD99BDB2-6F9C-4141-AE1E-919764CD000A"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:relion_620_ansi:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2A89CD0B-3990-47B0-9129-2BD5951F8C9B"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:relion_620_iec_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "315BBD9A-D5ED-4864-B12D-1C95515E7818", "versionEndExcluding": "2.1.15"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:relion_620_iec:2.0:fp1:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CD43DF9B-4D26-4B59-BADA-F333D7E2815D"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:relion_620_cn_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0BEA650E-EFD1-445D-8022-5C512E98B485", "versionEndExcluding": "2.1.15"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:relion_620_cn:2.0:fp1:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "806460AF-BC4A-4584-8172-20092865AEEF"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "cybersecurity@ch.abb.com"}