CVE-2021-27196

HIGHCVSS 7.5/10EPSS 1.57%

Last modified

CVE-2021-27196 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Improper Input Validation vulnerability in Hitachi ABB Power Grids Relion 670 Series, Relion 670/650 Series, Relion 670/650/SAM600-IO, Relion 650, REB500, RTU500 Series, FOX615 (TEGO1), MSM, GMS600, PWC600 allows an attacker with access to the IEC 61850 network with knowledge of how to reproduce the attack, as well as the IP addresses of the different IEC 61850 access points (of IEDs/products), to force the device to reboot, which renders the device inoperable for approximately 60 seconds. This vulnerability affects only products with IEC 61850 interfaces. EPSS estimates a 1.57% chance of exploitation in the next 30 days.

Description

Improper Input Validation vulnerability in Hitachi ABB Power Grids Relion 670 Series, Relion 670/650 Series, Relion 670/650/SAM600-IO, Relion 650, REB500, RTU500 Series, FOX615 (TEGO1), MSM, GMS600, PWC600 allows an attacker with access to the IEC 61850 network with knowledge of how to reproduce the attack, as well as the IP addresses of the different IEC 61850 access points (of IEDs/products), to force the device to reboot, which renders the device inoperable for approximately 60 seconds. This vulnerability affects only products with IEC 61850 interfaces. This issue affects: Hitachi ABB Power Grids Relion 670 Series 1.1; 1.2.3 versions prior to 1.2.3.20; 2.0 versions prior to 2.0.0.13; 2.1; 2.2.2 versions prior to 2.2.2.3; 2.2.3 versions prior to 2.2.3.2. Hitachi ABB Power Grids Relion 670/650 Series 2.2.0 versions prior to 2.2.0.13. Hitachi ABB Power Grids Relion 670/650/SAM600-IO 2.2.1 versions prior to 2.2.1.6. Hitachi ABB Power Grids Relion 650 1.1; 1.2; 1.3 versions prior to 1.3.0.7. Hitachi ABB Power Grids REB500 7.3; 7.4; 7.5; 7.6; 8.2; 8.3. Hitachi ABB Power Grids RTU500 Series 7.x version 7.x and prior versions; 8.x version 8.x and prior versions; 9.x version 9.x and prior versions; 10.x version 10.x and prior versions; 11.x version 11.x and prior versions; 12.x version 12.x and prior versions. Hitachi ABB Power Grids FOX615 (TEGO1) R1D02 version R1D02 and prior versions. Hitachi ABB Power Grids MSM 2.1.0 versions prior to 2.1.0. Hitachi ABB Power Grids GMS600 1.3.0 version 1.3.0 and prior versions. Hitachi ABB Power Grids PWC600 1.0 versions prior to 1.0.1.4; 1.1 versions prior to 1.1.0.1.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
1.57%

72.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HitachienergyRelion 670 Firmware>= 1.2.3, < 1.2.3.20
HitachienergyRelion 670 Firmware>= 2.0, < 2.0.0.13
HitachienergyRelion 670 Firmware>= 2.2.0, < 2.2.0.13
HitachienergyRelion 670 Firmware>= 2.2.1, < 2.2.1.6
HitachienergyRelion 670 Firmware>= 2.2.2, < 2.2.2.3
HitachienergyRelion 670 Firmware>= 2.2.3, < 2.2.3.2
HitachienergyRelion 670 Firmware1.1
HitachienergyRelion 670 Firmware2.1
HitachienergyRelion 650 Firmware>= 1.3, < 1.3.0.7
HitachienergyRelion 650 Firmware>= 2.2.0, < 2.2.0.13
HitachienergyRelion 650 Firmware>= 2.2.1, < 2.2.1.6
HitachienergyRelion 650 Firmware1.1
HitachienergyRelion 650 Firmware1.2
HitachienergyRelion 650 Firmware2.1
HitachienergyRelion Sam600-Io Firmware>= 2.2.1, < 2.2.1.6
HitachienergyRtu500 Firmware7.0
HitachienergyRtu500 Firmware8.0
HitachienergyRtu500 Firmware9.0
HitachienergyRtu500 Firmware10.0
HitachienergyRtu500 Firmware11.0
HitachienergyRtu500 Firmware12.0
HitachienergyReb500 Firmware>= 7.3, < 7.60.19
HitachienergyReb500 Firmware>= 8.2, < 8.2.0.5
HitachienergyReb500 Firmware>= 8.3, <= 8.3.1.0
HitachienergyFox615 Tego1 Firmware< r2a16
HitachienergyModular Switchgear Monitoring Firmware< 2.1.0
HitachienergyGms600 Firmware<= 1.3.0
HitachienergyPwc600 Firmware>= 1.0, < 1.0.1.4
HitachienergyPwc600 Firmware>= 1.1, < 1.1.0.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-27196?
Improper Input Validation vulnerability in Hitachi ABB Power Grids Relion 670 Series, Relion 670/650 Series, Relion 670/650/SAM600-IO, Relion 650, REB500, RTU500 Series, FOX615 (TEGO1), MSM, GMS600, PWC600 allows an attacker with access to the IEC 61850 network with knowledge of how to reproduce the attack, as well as the IP addresses of the different IEC 61850 access points (of IEDs/products), to force the device to reboot, which renders the device inoperable for approximately 60 seconds. This vulnerability affects only products with IEC 61850 interfaces. This issue affects: Hitachi ABB Power Grids Relion 670 Series 1.1; 1.2.3 versions prior to 1.2.3.20; 2.0 versions prior to 2.0.0.13; 2.1; 2.2.2 versions prior to 2.2.2.3; 2.2.3 versions prior to 2.2.3.2. Hitachi ABB Power Grids Relion 670/650 Series 2.2.0 versions prior to 2.2.0.13. Hitachi ABB Power Grids Relion 670/650/SAM600-IO 2.2.1 versions prior to 2.2.1.6. Hitachi ABB Power Grids Relion 650 1.1; 1.2; 1.3 versions prior to 1.3.0.7. Hitachi ABB Power Grids REB500 7.3; 7.4; 7.5; 7.6; 8.2; 8.3. Hitachi ABB Power Grids RTU500 Series 7.x version 7.x and prior versions; 8.x version 8.x and prior versions; 9.x version 9.x and prior versions; 10.x version 10.x and prior versions; 11.x version 11.x and prior versions; 12.x version 12.x and prior versions. Hitachi ABB Power Grids FOX615 (TEGO1) R1D02 version R1D02 and prior versions. Hitachi ABB Power Grids MSM 2.1.0 versions prior to 2.1.0. Hitachi ABB Power Grids GMS600 1.3.0 version 1.3.0 and prior versions. Hitachi ABB Power Grids PWC600 1.0 versions prior to 1.0.1.4; 1.1 versions prior to 1.1.0.1.
How severe is CVE-2021-27196?
CVE-2021-27196 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 1.57% probability of exploitation in the next 30 days.
How do I fix CVE-2021-27196?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-27196?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST