Back

HIGH

A vulnerability exists in the HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product

Published Jul 26, 2023

Description

A vulnerability exists in the HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-5 and the CMU contains the license feature ‘Advanced security’ which must be ordered separately. If these preconditions are fulfilled, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500, causing the targeted RTU500 CMU to reboot. The vulnerability is caused by a missing input data validation which eventually if exploited causes an internal buffer to overflow in the HCI IEC 60870-5-104 function.

Affected products

Remediation

Vendor solution

Update to CMU Firmware versions 13.3.3 or 13.4.1.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Hitachi Energy
Published Jul 26, 2023
Updated Mar 5, 2025
Reserved Jul 21, 2022
CISA Vulnrichment
Updated Mar 5, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Hitachi Energy
Published Jul 26, 2023
Updated Mar 5, 2025
Exploited since n/a
EUVD-2022-34760