Back

HIGH

Specially Crafted Modbus TCP Packet Vulnerability in RTU500 series

Published May 2, 2022

Description

A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is en-abled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500, causing the receiving RTU500 CMU to reboot. The vulnerability is caused by the validation error in the length information carried in MBAP header in the HCI Modbus TCP function.

Affected products

Remediation

Vendor solution

Remediation available, see the advisory for details.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Hitachi Energy
Published May 2, 2022
Updated Sep 25, 2024
Reserved Apr 4, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Hitachi Energy
Published May 2, 2022
Updated Sep 25, 2024
Exploited since n/a
EUVD-2022-33055