GE Hydran M2 Predictable Value Range from Previous Values

Summary

CVECVE-2014-5409
StatePUBLISHED
Assignericscert
Source PriorityCVE Program / NVD first with legacy fallback
Published2015-03-14 01:59:00 UTC
Updated2026-05-06 22:30:45 UTC
DescriptionThe 17046 Ethernet card before 94450214LFMT100SEM-L.R3-CL for the GE Digital Energy Hydran M2 does not properly generate random values for TCP Initial Sequence Numbers (ISNs), which makes it easier for remote attackers to spoof packets by predicting these values.

Risk And Classification

Primary CVSS: v2.0 5 from [email protected]

AV:N/AC:L/Au:N/C:P/I:N/A:N

Problem Types: CWE-343 | NVD-CWE-Other | CWE-343 CWE-343


VersionSourceTypeScoreSeverityVector
2.0[email protected]Primary5AV:N/AC:L/Au:N/C:P/I:N/A:N
2.0[email protected]Secondary6.4AV:N/AC:L/Au:N/C:P/I:N/A:P
2.0CNACVSS6.4AV:N/AC:L/Au:N/C:P/I:N/A:P

CVSS v2.0 Breakdown

Access Vector
Network
Access Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None

AV:N/AC:L/Au:N/C:P/I:N/A:N

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Hardware Ge Hydran M2 All All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA GE Hydran M2 Containing The 17046 Ethernet Option affected October 2014 custom Not specified

References

ReferenceSourceLinkTags
GE Hydran M2 Predictable TCP Initial Sequence Vulnerability | ICS-CERT af854a3a-2127-422b-91ae-364da2661108 ics-cert.us-cert.gov Third Party Advisory, US Government Resource
github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2015/icsa-15-04... [email protected] github.com
www.cisa.gov/news-events/ics-advisories/icsa-15-041-02 [email protected] www.cisa.gov
SSO login for SupportCentral af854a3a-2127-422b-91ae-364da2661108 libraries.ge.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Vendor Comments And Credit

Discovery Credit

CNA: Raheem Beyah, David Formby, and San Shin Jung of Georgia Tech (en)

Additional Advisory Data

Solutions

CNA: GE Digital Energy has released a new version of the Ethernet option, which resolves the identified vulnerability in newly released Hydran M2 devices. The update changes the sequence algorithm, which makes it improbable that a TCP sequence attack could succeed. The version of Ethernet card that implements this improvement is 94450214LFMT100SEM-L.R3-CL.

Workarounds

CNA: There is no method to update Hydran M2 devices released prior to October 2014. GE Digital Energy recommends that utilities using older versions of the Hydran M2 device implement network security defensive measures, to include the following: •     Place the Hydran M2 inside the control system network security perimeter with access controls and monitoring. •     Minimize network exposure to all other control system devices. Control system devices should not directly face the Internet or business networks. •     Locate control system networks and devices behind properly configured firewalls, and isolate them from the business network. •     When remote access is required, use secure methods, such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize that VPN is only as secure as the connected devices. GE Digital Energy’s Product Bulletin is available in at the following location, with a user account: http://libraries.ge.com/download?fileid=642886573101&entity_id=31955841101&sid=101

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report