{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-29T13:08:10.544","vulnerabilities":[{"cve":{"id":"CVE-2017-7905","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2017-06-30T03:29:00.890","lastModified":"2026-06-17T01:25:26.070","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 469 Motor Protection Relay, firmware versions prior to Version 5.23; SR 489 Generator Protection Relay, firmware versions prior to Version 4.06; SR 745 Transformer Protection Relay, firmware versions prior to Version 5.23; SR 369 Motor Protection Relay, all firmware versions; Multilin Universal Relay, firmware Version 6.0 and prior versions; and Multilin URplus (D90, C90, B95), all versions. Ciphertext versions of user passwords were created with a non-random initialization vector leaving them susceptible to dictionary attacks. Ciphertext of user passwords can be obtained from the front LCD panel of affected products and through issued Modbus commands."},{"lang":"es","value":"Se ha descubierto un problema de criptografía débil para contraseñas en General Electric (GE) Multilin SR 750 Feeder Protection Relay con versiones de firmware anteriores a la versión 7.47."}],"affected":[{"source":"ics-cert@hq.dhs.gov","affectedData":[{"vendor":"n/a","product":"GE Multilin SR, UR, and URplus Protective Relays","versions":[{"version":"GE Multilin SR, UR, and URplus Protective Relays","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-261"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-326"},{"lang":"en","value":"CWE-330"},{"lang":"en","value":"CWE-522"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ge:multilin_sr_750_feeder_protection_relay_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"5.02","matchCriteriaId":"F9CDB455-F6F8-4976-95D2-88D21720DE88"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ge:multilin_sr_750_feeder_protection_relay:-:*:*:*:*:*:*:*","matchCriteriaId":"6E636C33-148B-4C26-96B3-CA0D1575C26D"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ge:multilin_sr_760_feeder_protection_relay_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"5.02","matchCriteriaId":"FDE8714B-96AC-4A85-ADCC-D00F54803596"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ge:multilin_sr_760_feeder_protection_relay:-:*:*:*:*:*:*:*","matchCriteriaId":"22504FF2-C1B7-406C-B253-ED7982A624D5"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ge:multilin_sr_469_motor_protection_relay_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"2.90","matchCriteriaId":"9928DE28-CE5A-4AC2-A956-D128764720BA"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ge:multilin_sr_469_motor_protection_relay:-:*:*:*:*:*:*:*","matchCriteriaId":"D6A23088-B5C4-4B0A-9E92-12946555C8A0"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ge:multilin_sr_489_generator_protection_relay_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.53","matchCriteriaId":"8766AA67-18A8-4440-BED6-E6BBDF3EF78D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ge:multilin_sr_489_generator_protection_relay:-:*:*:*:*:*:*:*","matchCriteriaId":"E899C89E-89EE-4FC1-809D-E6DB04989B28"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ge:multilin_sr_745_transformer_protection_relay_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"2.85","matchCriteriaId":"F032369D-581E-4FCA-85CA-B932CB1E821D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ge:multilin_sr_745_transformer_protection_relay:-:*:*:*:*:*:*:*","matchCriteriaId":"DA36A160-426F-4911-9CF3-28E496AEDDB7"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ge:multilin_sr_369_motor_protection_relay_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"32F15979-2C0D-4DD6-BA35-C5300EEF752D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ge:multilin_sr_369_motor_protection_relay:-:*:*:*:*:*:*:*","matchCriteriaId":"1CA749D2-FCF4-4936-84AA-EF317BB6DEEB"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ge:multilin_universal_relay_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"6.0","matchCriteriaId":"C329C25F-D48E-4B39-8FDB-88CE14E1D285"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ge:multilin_universal_relay:-:*:*:*:*:*:*:*","matchCriteriaId":"84392E96-D1C4-438C-ABA9-DE1384623D5A"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ge:multilin_urplus_d90_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"36F9ACC9-EDE7-42E8-AF34-057EA862147D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ge:multilin_urplus_d90:-:*:*:*:*:*:*:*","matchCriteriaId":"3C697E8E-28F2-43F9-9B7D-0BF939B2F220"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ge:multilin_urplus_c90_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"DBEF4ACF-7851-4EA2-B6E8-D60DB0BC660B"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ge:multilin_urplus_c90:-:*:*:*:*:*:*:*","matchCriteriaId":"E16FE6EA-BB44-4B73-BFA5-30E1ADF5D522"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ge:multilin_urplus_b95_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"11D188B6-4ADD-4FA6-9FF4-35B813911398"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ge:multilin_urplus_b95:-:*:*:*:*:*:*:*","matchCriteriaId":"93C57507-A23D-4DF7-9D9B-3531F2235132"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/98063","source":"ics-cert@hq.dhs.gov","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-117-01A","source":"ics-cert@hq.dhs.gov","tags":["Patch","Third Party Advisory","US Government Resource"]},{"url":"http://www.securityfocus.com/bid/98063","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-117-01A","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory","US Government Resource"]}]}}]}