CVE-2017-7905 Details
Description
A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 469 Motor Protection Relay, firmware versions prior to Version 5.23; SR 489 Generator Protection Relay, firmware versions prior to Version 4.06; SR 745 Transformer Protection Relay, firmware versions prior to Version 5.23; SR 369 Motor Protection Relay, all firmware versions; Multilin Universal Relay, firmware Version 6.0 and prior versions; and Multilin URplus (D90, C90, B95), all versions. Ciphertext versions of user passwords were created with a non-random initialization vector leaving them susceptible to dictionary attacks. Ciphertext of user passwords can be obtained from the front LCD panel of affected products and through issued Modbus commands.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://ics-cert.us-cert.gov/advisories/ICSA-17-117-01A | CVE | PatchThird Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/98063 | CVE | Third Party AdvisoryVDB Entry |
| https://ics-cert.us-cert.gov/advisories/ICSA-17-117-01A | [email protected] | PatchThird Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/98063 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-326 | Inadequate Encryption Strength | [email protected] |
| CWE-330 | Use of Insufficiently Random Values | [email protected] |
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
| CWE-261 | Weak Encoding for Password | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ge multilin sr 750 feeder protection relay firmware | <= 5.02 |
CPE
Remediation
| |
| ge multilin sr 750 feeder protection relay | All versions |
CPE
Remediation
| |
| ge multilin sr 760 feeder protection relay firmware | <= 5.02 |
CPE
Remediation
| |
| ge multilin sr 760 feeder protection relay | All versions |
CPE
Remediation
| |
| ge multilin sr 469 motor protection relay firmware | <= 2.90 |
CPE
Remediation
| |
| ge multilin sr 469 motor protection relay | All versions |
CPE
Remediation
| |
| ge multilin sr 489 generator protection relay firmware | <= 1.53 |
CPE
Remediation
| |
| ge multilin sr 489 generator protection relay | All versions |
CPE
Remediation
| |
| ge multilin sr 745 transformer protection relay firmware | <= 2.85 |
CPE
Remediation
| |
| ge multilin sr 745 transformer protection relay | All versions |
CPE
Remediation
| |
| ge multilin sr 369 motor protection relay firmware | All versions |
CPE
Remediation
| |
| ge multilin sr 369 motor protection relay | All versions |
CPE
Remediation
| |
| ge multilin universal relay firmware | <= 6.0 |
CPE
Remediation
| |
| ge multilin universal relay | All versions |
CPE
Remediation
| |
| ge multilin urplus d90 firmware | All versions |
CPE
Remediation
| |
| ge multilin urplus d90 | All versions |
CPE
Remediation
| |
| ge multilin urplus c90 firmware | All versions |
CPE
Remediation
| |
| ge multilin urplus c90 | All versions |
CPE
Remediation
| |
| ge multilin urplus b95 firmware | All versions |
CPE
Remediation
| |
| ge multilin urplus b95 | All versions |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Oct 3, 2019 | CWE Remap | [email protected] |
| Jul 14, 2017 | Initial Analysis | [email protected] |
| Jul 1, 2017 | CVE Modified | [email protected] |