# CVE-2014-5409

## Summary

- **CVE ID:** CVE-2014-5409
- **Severity:** UNKNOWN
- **CVSS Score:** 6.4 (AV:N/AC:L/Au:N/C:P/I:N/A:P)
- **CWE:** CWE-343
- **Published:** Mar 14, 2015
- **Last Modified:** Mar 15, 2026

## Description

The 17046 Ethernet card before 94450214LFMT100SEM-L.R3-CL for the GE Digital Energy Hydran M2 does not properly generate random values for TCP Initial Sequence Numbers (ISNs), which makes it easier for remote attackers to spoof packets by predicting these values.

## Affected Products

- GE — Hydran M2, containing the 17046 Ethernet option (0)

## References

- [CNA](https://www.cisa.gov/news-events/ics-advisories/icsa-15-041-02)
- [CNA](http://libraries.ge.com/download?fileid=642886573101&entity_id=31955841101&sid=101)
- [CNA](https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2015/icsa-15-041-02.json)
- [CVE](https://ics-cert.us-cert.gov/advisories/ICSA-15-041-02)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 2.29%
- **EPSS Percentile:** 84.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._