CVE-2014-9196

Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and IdeaPLUS relays generates TCP initial sequence number (ISN) values linearly, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:eaton:proview:4.0:*:*:*:*:*:*:*
cpe:2.3:a:eaton:proview:5.0:*:*:*:*:*:*:*
cpe:2.3:a:eaton:proview:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:eaton:proview:5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:eaton:proview:5.0.3:*:*:*:*:*:*:*
cpe:2.3:a:eaton:proview:5.0.4:*:*:*:*:*:*:*
cpe:2.3:a:eaton:proview:5.0.5:*:*:*:*:*:*:*
cpe:2.3:a:eaton:proview:5.0.6:*:*:*:*:*:*:*
cpe:2.3:a:eaton:proview:5.0.7:*:*:*:*:*:*:*
cpe:2.3:a:eaton:proview:5.0.8:*:*:*:*:*:*:*
cpe:2.3:a:eaton:proview:5.0.9:*:*:*:*:*:*:*
cpe:2.3:a:eaton:proview:5.0.10:*:*:*:*:*:*:*

History

05 Sep 2025, 21:15

Type Values Removed Values Added
References
  • () https://www.cisa.gov/news-events/ics-advisories/icsa-15-006-01 -
  • () https://www.eaton.com/cybersecurity -
CVSS v2 : 9.3
v3 : unknown
v2 : 7.6
v3 : unknown
CWE CWE-342

Information

Published : 2015-07-20 01:59

Updated : 2025-09-05 21:15


NVD link : CVE-2014-9196

Mitre link : CVE-2014-9196

CVE.ORG link : CVE-2014-9196


JSON object : View

Products Affected

eaton

  • proview
CWE
CWE-342

Predictable Exact Value from Previous Values

CWE-254

7PK - Security Features