CVE-2014-5409

Summary

The 17046 Ethernet card before 94450214LFMT100SEM-L.R3-CL for the GE Digital Energy Hydran M2 does not properly generate random values for TCP Initial Sequence Numbers (ISNs), which makes it easier for remote attackers to spoof packets by predicting these values.

Affected Software

VendorProductVersion RangeStatus
GEHydran M2, containing the 17046 Ethernet option0 < October 2014affected

Weaknesses

  • CWE-343: CWE-343

Workarounds

There is no method to update Hydran M2 devices released prior to October 2014. GE Digital Energy recommends that utilities using older versions of the Hydran M2 device implement network security defensive measures, to include the following:

•     Place the Hydran M2 inside the control system network security perimeter with access controls and monitoring.

•     Minimize network exposure to all other control system devices. Control system devices should not directly face the Internet or business networks.

•     Locate control system networks and devices behind properly configured firewalls, and isolate them from the business network.

•     When remote access is required, use secure methods, such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize that VPN is only as secure as the connected devices.

GE Digital Energy’s Product Bulletin is available in at the following location, with a user account:

http://libraries.ge.com/download?fileid=642886573101&amp;entity_id=31955841101&amp;sid=101

ADP Enrichment

CVE Program Container

Additional References

References