A vulnerability exists in the HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product
Published Jul 26, 2023
7.5
HIGHCVSS 3.1
EPSS 0.65%
Description
A vulnerability exists in the HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-5 and the CMU contains the license feature ‘Advanced security’ which must be ordered separately. If these preconditions are fulfilled, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500, causing the targeted RTU500 CMU to reboot. The vulnerability is caused by a missing input data validation which eventually if exploited causes an internal buffer to overflow in the HCI IEC 60870-5-104 function.
Affected products
-
- Version RTU500 series CMU Firmware version 13.3.1StatusaffectedConstraints-
- Version RTU500 series CMU Firmware version 13.3.2StatusaffectedConstraints-
- Version RTU500 series CMU Firmware version 13.3.3StatusunaffectedConstraints-
- Version RTU500 series CMU Firmware version 13.4.1StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Hitachi Energy | RTU500 series | unaffected |
|
- 13.3.1
- 13.3.2
- 13.3.3
- 13.4.1
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update to CMU Firmware versions 13.3.3 or 13.4.1.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-34760 Advisory
- https://publisher.hitachienergy.com/preview?DocumentID=8DBD000121&LanguageCode=en&DocumentPartId=&Action=Launch vendor-advisory
- https://search.abb.com/library/Download.aspx?DocumentID=8DBD000121&LanguageCode=en&DocumentPartId=&Action=Launch
Change history (0)
No recorded changes yet.