CVE-2014-9201

UnknownEPSS 1.56%

Last modified

CVE-2014-9201 is a vulnerability of currently unknown severity. Beckwith Electric M-6200 Digital Voltage Regulator Control with firmware before D-0198V04.07.00, M-6200A Digital Voltage Regulator Control with firmware before D-0228V02.01.07, M-2001D Digital Tapchanger Control with firmware before D-0214V01.10.04, M-6283A Three Phase Digital Capacitor Bank Control with firmware before D-0346V03.00.02, M-6280A Digital Capacitor Bank Control with firmware before D-0254V03.05.05, and M-6280 Digital Capacitor Bank Control do not properly generate TCP initial sequence number (ISN) values, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.. EPSS estimates a 1.56% chance of exploitation in the next 30 days.

Description

Beckwith Electric M-6200 Digital Voltage Regulator Control with firmware before D-0198V04.07.00, M-6200A Digital Voltage Regulator Control with firmware before D-0228V02.01.07, M-2001D Digital Tapchanger Control with firmware before D-0214V01.10.04, M-6283A Three Phase Digital Capacitor Bank Control with firmware before D-0346V03.00.02, M-6280A Digital Capacitor Bank Control with firmware before D-0254V03.05.05, and M-6280 Digital Capacitor Bank Control do not properly generate TCP initial sequence number (ISN) values, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.

Metrics

EPSS Probability
1.56%

72.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
BeckwithelectricM-2001d Digital Tapchanger ControlAll versions
BeckwithelectricM-6200 Digital Voltage Regulator ControlAll versions
BeckwithelectricM-6200a Digital Voltage Regulator ControlAll versions
BeckwithelectricM-6280 Digital Capacitor Bank ControlAll versions
BeckwithelectricM-6280a Digital Capacitor Bank ControlAll versions
BeckwithelectricM-6283a Three Phase Digital Capacitor Bank ControlAll versions
BeckwithelectricM-2001d Digital Tapchanger Control D-0214 Firmware<= 01.10.04
BeckwithelectricM-6200 Digital Voltage Regulator Control D-0198 Firmware<= 04.07.00
BeckwithelectricM-6200a Digital Voltage Regulator Control D-0228 Firmware<= 02.01.07
BeckwithelectricM-6280 Digital Capacitor Bank Control FirmwareAll versions
BeckwithelectricM-6280a Digital Capacitor Bank Control D-0254 Firmware<= 03.05.05
BeckwithelectricM-6283a Three Phase Digital Capacitor Bank Control D-0346 Firmware<= 03.00.02

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-9201?
Beckwith Electric M-6200 Digital Voltage Regulator Control with firmware before D-0198V04.07.00, M-6200A Digital Voltage Regulator Control with firmware before D-0228V02.01.07, M-2001D Digital Tapchanger Control with firmware before D-0214V01.10.04, M-6283A Three Phase Digital Capacitor Bank Control with firmware before D-0346V03.00.02, M-6280A Digital Capacitor Bank Control with firmware before D-0254V03.05.05, and M-6280 Digital Capacitor Bank Control do not properly generate TCP initial sequence number (ISN) values, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.
How severe is CVE-2014-9201?
Severity scoring for CVE-2014-9201 is pending analysis. The EPSS model estimates a 1.56% probability of exploitation in the next 30 days.
How do I fix CVE-2014-9201?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-9201?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST