Vulnerability CVE-2014-9201


Published: 2015-06-05

Description:
Beckwith Electric M-6200 Digital Voltage Regulator Control with firmware before D-0198V04.07.00, M-6200A Digital Voltage Regulator Control with firmware before D-0228V02.01.07, M-2001D Digital Tapchanger Control with firmware before D-0214V01.10.04, M-6283A Three Phase Digital Capacitor Bank Control with firmware before D-0346V03.00.02, M-6280A Digital Capacitor Bank Control with firmware before D-0254V03.05.05, and M-6280 Digital Capacitor Bank Control do not properly generate TCP initial sequence number (ISN) values, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.4/10
4.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
Partial
Affected software
Beckwithelectric -> M-2001d digital tapchanger control 
Beckwithelectric -> M-6200 digital voltage regulator control 
Beckwithelectric -> M-6200a digital voltage regulator control 
Beckwithelectric -> M-6280 digital capacitor bank control 
Beckwithelectric -> M-6280a digital capacitor bank control 
Beckwithelectric -> M-6283a three phase digital capacitor bank control 
Beckwithelectric -> M-2001d digital tapchanger control d-0214 firmware 
Beckwithelectric -> M-6200 digital voltage regulator control d-0198 firmware 
Beckwithelectric -> M-6200a digital voltage regulator control d-0228 firmware 
Beckwithelectric -> M-6280 digital capacitor bank control firmware 
Beckwithelectric -> M-6280a digital capacitor bank control d-0254 firmware 
Beckwithelectric -> M-6283a three phase digital capacitor bank control d-0346 firmware 

 References:
https://ics-cert.us-cert.gov/advisories/ICSA-15-153-01

Copyright 2024, cxsecurity.com

 

Back to Top