GE Hydran M2 Predictable Value Range from Previous Values
Summary
| CVE | CVE-2014-5409 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-03-14 01:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The 17046 Ethernet card before 94450214LFMT100SEM-L.R3-CL for the GE Digital Energy Hydran M2 does not properly generate random values for TCP Initial Sequence Numbers (ISNs), which makes it easier for remote attackers to spoof packets by predicting these values. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
Problem Types: CWE-343 | NVD-CWE-Other | CWE-343 CWE-343
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:P/I:N/A:N | |
| 2.0 | [email protected] | Secondary | 6.4 | AV:N/AC:L/Au:N/C:P/I:N/A:P | |
| 2.0 | CNA | CVSS | 6.4 | AV:N/AC:L/Au:N/C:P/I:N/A:P |
CVSS v2.0 Breakdown
AV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | GE | Hydran M2 Containing The 17046 Ethernet Option | affected October 2014 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GE Hydran M2 Predictable TCP Initial Sequence Vulnerability | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2015/icsa-15-04... | [email protected] | github.com | |
| www.cisa.gov/news-events/ics-advisories/icsa-15-041-02 | [email protected] | www.cisa.gov | |
| SSO login for SupportCentral | af854a3a-2127-422b-91ae-364da2661108 | libraries.ge.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Raheem Beyah, David Formby, and San Shin Jung of Georgia Tech (en)
Additional Advisory Data
Solutions
CNA: GE Digital Energy has released a new version of the Ethernet option, which resolves the identified vulnerability in newly released Hydran M2 devices. The update changes the sequence algorithm, which makes it improbable that a TCP sequence attack could succeed. The version of Ethernet card that implements this improvement is 94450214LFMT100SEM-L.R3-CL.
Workarounds
CNA: There is no method to update Hydran M2 devices released prior to October 2014. GE Digital Energy recommends that utilities using older versions of the Hydran M2 device implement network security defensive measures, to include the following: • Place the Hydran M2 inside the control system network security perimeter with access controls and monitoring. • Minimize network exposure to all other control system devices. Control system devices should not directly face the Internet or business networks. • Locate control system networks and devices behind properly configured firewalls, and isolate them from the business network. • When remote access is required, use secure methods, such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize that VPN is only as secure as the connected devices. GE Digital Energy’s Product Bulletin is available in at the following location, with a user account: http://libraries.ge.com/download?fileid=642886573101&entity_id=31955841101&sid=101