Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2017-7905

9.8 · CRITICAL
Published Jun 30, 2017 ge CWE-261

Overview

CVE-2017-7905 is a critical-severity vulnerability affecting ge multilin_sr_750_feeder_protection_relay_firmware. It was published on June 30, 2017 and has a CVSS 3.0 base score of 9.8 (CRITICAL).

This vulnerability has a CVSS 3.0 base score of 9.8, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 469 Motor Protection Relay, firmware versions prior to Version 5.23; SR 489 Generator Protection Relay, firmware versions prior to Version 4.06; SR 745 Transformer Protection Relay, firmware versions prior to Version 5.23; SR 369 Motor Protection Relay, all firmware versions; Multilin Universal Relay, firmware Version 6.0 and prior versions; and Multilin URplus (D90, C90, B95), all versions. Ciphertext versions of user passwords were created with a non-random initialization vector leaving them susceptible to dictionary attacks. Ciphertext of user passwords can be obtained from the front LCD panel of affected products and through issued Modbus commands.

Remediation

Check the references section for vendor advisories and patches from ge. Update multilin_sr_750_feeder_protection_relay_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
ge multilin_sr_750_feeder_protection_relay_firmware 0 Affected
ge multilin_sr_760_feeder_protection_relay_firmware 0 Affected
ge multilin_sr_469_motor_protection_relay_firmware 0 Affected
ge multilin_sr_489_generator_protection_relay_firmware 0 Affected
ge multilin_sr_745_transformer_protection_relay_firmware 0 Affected
ge multilin_universal_relay_firmware 0 Affected

Frequently Asked Questions

What is CVE-2017-7905?

CVE-2017-7905 is a critical-severity vulnerability affecting ge multilin_sr_750_feeder_protection_relay_firmware. It was published on June 30, 2017 and has a CVSS 3.0 base score of 9.8 (CRITICAL).

How severe is CVE-2017-7905?

This vulnerability has a CVSS 3.0 base score of 9.8, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2017-7905?

Check the references section for vendor advisories and patches from ge. Update multilin_sr_750_feeder_protection_relay_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2017-7905?

CyberStrike's AI-powered security agents can automatically detect CVE-2017-7905 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.