QID 591395
Date Published: 2023-04-03
QID 591395: General Electric Universal Relay (UR) family of products Distributed Network Protocol (DNP3) Implementation Vulnerability (GET-20046A)
AFFECTED PRODUCTS
GE Universal Relay (UR) family of products.
Applicable to products: B30, B90, C30, C60, C70, D30, D60, F35, F60, G30, G60, L30, L60, L90, M60, N60, T35, T60
Impacted versions: Up to 6.05, 7.00 to 7.20
Action: Upgrade to version 6.06, 7.21 or later
QID Detection Logic:
This QID checks for the Vulnerable version of General Electric Universal Relay (UR) family of products using passive scanning.
A vulnerability has been identified in the UR product line that can result in denial of service to the DNP slave functionality on the UR, requiring a power cycle to the relay to recover. This vulnerability is accessible via serial or Internet protocol (IP) based networks and affects the UR firmware versions identified. Network interfaces that utilize the Transmission Control Protocol (TCP) can be exploited remotely, but serial access is not exploitable remotely and local access to the serial-based outstation is required.
Customers are advised to refer to CERT MITIGATIONS section GET-20046A for affected packages and patching details.
CVEs related to QID 591395
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GET-20046A |
|