
UR Family Firmware 5.84 - Release Notes
25
Description: In previous versions, the Phase Distance element zone 2 operate operand drops out 20 msec
after the pickup operand. In the new releases, the zone 2 operate drops out at the same time as the
pickup operand.
GE tracking number: 607-2
Communications
C
Improved security of UR web pages
Products: All
Impacted firmware: All to 8.03
Corrected firmware: 5.84, 6.07, 7.28, 8.10
Workaround: Secure access to the relay’s web pages by strong security practices in the substation
Description: The new release includes a number of security enhancements to prevent possible corruption
of the relay’s web pages by a malicious user.
GE tracking number: 810-10
C
Corrected issues with HardFiber contact inputs
Products: All with HardFiber
Impacted firmware: All to 7.32
Corrected firmware: 5.84, 7.40
Workaround: None
Description: In the case of intermittent communications failure between the HardFiber and the Process
Bus Card, multiple events can be logged into the event recorder indicating status change of the field
contact outputs and inputs. This happens due to last valid status values being substituted with default
values if even one sample is detected as bad in the frame. With the new release, at least two bad frames
are required (two protection passes) to substitute the field contact inputs and outputs with default status
values.
GE tracking number: 740-27
Cyber security
C
Fixed predictable TCP sequence number vulnerability in VxWorks 5.3.1 (CVE-2015-3963)
Products: All
Impacted firmware: All to 6.05
Corrected firmware: 5.84, 6.06
Workaround: None
Description: In previous versions, the Wind River VxWorks is subject to a vulnerability described in
NIST CVE-2015-3963 vulnerability report
. In version 6.06, this issue is fixed.
GE tracking number: 606-1
G
Fixed firmware to address VxWorks vulnerability described in ICS-CERT Advisory ICSA-10-214-01)
Products: All
Impacted firmware: All to 5.47, 5.80 to 5.82, 5.90 to 5.91, 6.00 to 6.01
Corrected firmware: 5.84, 6.06, 7.26, 7.32, 7.40
Workaround: None
Description: The third-party Wind River VxWorks is subject to a vulnerability described in
. The VxWorks debug port is open by default. In the new releases, the
vulnerability is addressed. The debug port is disabled by default in versions 6.06, 7.26, 7.32, 7.40 or greater.