CVE-2021-22283

Improper Initialization vulnerability in ABB Relion protection relays - 611 series, ABB Relion protection relays - 615 series IEC 4.0 FP1, ABB Relion protection relays - 615 series CN 4.0 FP1, ABB Relion protection relays - 615 series IEC 5.0, ABB Relion protection relays - 615 series IEC 5.0 FP1, ABB Relion protection relays - 620 series IEC/CN 2.0, ABB Relion protection relays - 620 series IEC/CN 2.0 FP1, ABB Relion protection relays - REX640 PCL1, ABB Relion protection relays - REX640 PCL2, ABB Relion protection relays - REX640 PCL3, ABB Relion protection relays - RER615, ABB Remote Monitoring and Control - REC615, ABB Merging Unit- SMU615 allows Communication Channel Manipulation.This issue affects Relion protection relays - 611 series: from 1.0.0 before 2.0.3; Relion protection relays - 615 series IEC 4.0 FP1: from 4.1.0 before 4.1.9; Relion protection relays - 615 series CN 4.0 FP1: from 4.1.0 before 4.1.8; Relion protection relays - 615 series IEC 5.0: from 5.0.0 before 5.0.12; Relion protection relays - 615 series IEC 5.0 FP1: from 5.1.0 before 5.1.20; Relion protection relays - 620 series IEC/CN 2.0: from 2.0.0 before 2.0.11; Relion protection relays - 620 series IEC/CN 2.0 FP1: from 2.1.0 before 2.1.15; Relion protection relays - REX640 PCL1: from 1.0.0 before 1.0.8; Relion protection relays - REX640 PCL2: from 1.1.0 before 1.1.4; Relion protection relays - REX640 PCL3: from 1.2.0 before 1.2.1; Relion protection relays - RER615: from 2.0.0 before 2.0.3; Remote Monitoring and Control - REC615: from 1.0.0 before 2.0.3; Merging Unit- SMU615: from 1.0.0 before 1.0.2.

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.2 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ABBCNA
6.2 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
VendorProductVersion
abbsmu615_firmware
𝑥
< 1.0.2
abbrec615_firmware
𝑥
< 2.0.3
abbrer615_firmware
𝑥
< 2.0.3
abbevd4_firmware
*
abbref615r_firmware
*
abbrex640_pcl3_firmware
𝑥
< 1.2.1
abbrex640_pcl2_firmware
𝑥
< 1.1.4
abbrex640_pcl1_firmware
𝑥
< 1.0.8
abbrer620_firmware
*
abbrelion_611_firmware
𝑥
< 2.0.3
abbref615_iec_firmware
*
abbref615_ansi_firmware
*
abbref615_iec_firmware
*
abbred615_iec_firmware
*
abbref615_ansi_firmware
*
abbrelion_615_iec_firmware
*
abbrelion_615_cn_firmware
*
abbrelion_615_ansi_firmware
*
abbrelion_615_iec_firmware
𝑥
< 4.1.9
abbrelion_615_cn_firmware
𝑥
< 4.1.8
abbrelion_615_iec_firmware
𝑥
< 5.0.12
abbrelion_615_iec_firmware
𝑥
< 5.1.20
abbrelion_620_iec_firmware
𝑥
< 2.0.11
abbrelion_620_cn_firmware
𝑥
< 2.0.11
abbrelion_620_ansi_firmware
*
abbrelion_620_iec_firmware
𝑥
< 2.1.15
abbrelion_620_cn_firmware
𝑥
< 2.1.15
𝑥
= Vulnerable software versions