The 17046 Ethernet card before 94450214LFMT100SEM-L.R3-CL for the GE Digital Energy Hydran M2 does not properly generate random values for TCP Initial Sequence Numbers (ISNs), which makes it easier for remote attackers to spoof packets by predicting these values.
Advisories
Source ID Title
EUVD EUVD EUVD-2014-5297 The 17046 Ethernet card before 94450214LFMT100SEM-L.R3-CL for the GE Digital Energy Hydran M2 does not properly generate random values for TCP Initial Sequence Numbers (ISNs), which makes it easier for remote attackers to spoof packets by predicting these values.
Fixes

Solution

GE Digital Energy has released a new version of the Ethernet option, which resolves the identified vulnerability in newly released Hydran M2 devices. The update changes the sequence algorithm, which makes it improbable that a TCP sequence attack could succeed. The version of Ethernet card that implements this improvement is 94450214LFMT100SEM-L.R3-CL.


Workaround

There is no method to update Hydran M2 devices released prior to October 2014. GE Digital Energy recommends that utilities using older versions of the Hydran M2 device implement network security defensive measures, to include the following: •     Place the Hydran M2 inside the control system network security perimeter with access controls and monitoring. •     Minimize network exposure to all other control system devices. Control system devices should not directly face the Internet or business networks. •     Locate control system networks and devices behind properly configured firewalls, and isolate them from the business network. •     When remote access is required, use secure methods, such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize that VPN is only as secure as the connected devices. GE Digital Energy’s Product Bulletin is available in at the following location, with a user account: http://libraries.ge.com/download?fileid=642886573101&entity_id=31955841101&sid=101

History

Mon, 03 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Title GE Hydran M2 GE Hydran M2 Predictable Value Range from Previous Values

Mon, 03 Nov 2025 19:00:00 +0000

Type Values Removed Values Added
Title GE Hydran M2
Weaknesses CWE-343
References
Metrics cvssV2_0

{'score': 5.0, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N'}

cvssV2_0

{'score': 6.4, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-11-03T18:58:26.900Z

Reserved: 2014-08-22T00:00:00

Link: CVE-2014-5409

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2015-03-14T01:59:00.067

Modified: 2025-11-03T19:15:39.013

Link: CVE-2014-5409

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.