CVE-2024-8036 - CVE House
Back to Database
Status published Medium CVE-2024-8036

Unauthorized Modifications of Firmware and Configuration

Vulnerability Description

ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE. An attacker could exploit these vulnerabilities by sending a specially crafted firmware or configuration to the system node, causing the node to stop, become inaccessible, or allowing the attacker to take control of the node.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-8036

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • ABB thanks Jos Wetzels from Midnight Blue (midnightblue.nl) for helping to identify the vulnerabilities and protecting our customers.

Affected Vendor

Affected Software

Relion Protection Relays RE_611 IEC, Relion Protection Relays REF615 IEC, Relion Protection Relays REF615 ANSI, Relion Protection Relays REX615, Relion Protection Relays REX610, Relion Protection Relays REX640, Substation Merging Unit SMU615, Smart Substation Control and Protection SSC600, Relion Protection Relays REF615R ANSI, Relion Protection Relays RED615 IEC, Relion Protection Relays 615 series IEC, Relion Protection Relays 615 series CN, Relion Protection Relays 615 series ANSI, Relion Protection Relays RER615, Relion Protection Relays REC615, RBX615, RER620 ANSI, 620 Series IEC/CN, RE_630, RIO600, COM600, SPA ZC-400, COM600F ANSI, SPA ZC-402, REF542plus, SUE 3000, ARG600/ARP600/ARR600/ARC600 single SIM, ARG600/ARP600 dual SIM, ARM600, REC601/RER601, REC603/RER603
Vulnerable Versions:
1.0.0, 2.0.0, PCL1, 1.1.1, 1.2.0, 1.1.0, 1.3.0, 1.0, 1.0 FP1, 1.0 FP2, 1.0 FP3, 1.0 FP4, 4.0.0, 3.0.0, 4.1.9, 5.0.0, 5.1.0, 3.1.0, 4.1.0, 4.2.0, 2.1.0, 3.3, 3.4, 3.5, 4.0, 4.1, 5.0, 5.1, Exx, Mxx, Sxx, xMx, Exxx, Mxxx, Sxxx, xMxx, xxxC, R1.0, R1.1, R2.0, R2.5, R2.5 ATEX, R2.5 SP3, R2.6, R3.0, R3.0 SP1, R3.0 SP3, 2.6 V4F07x, 3.0FP1 V4F11x, V4D02x, V4E0xx, 3.x.x, 2.x.x, 4.x.x, 1.1

Timeline

Official Publish: October 25th, 2024
Last Modified: October 30th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:H

Weaknesses (CWE)