Back

HIGH

A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product

Published Jul 26, 2023

Description

A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-3. After session resumption interval is expired an RTU500 initiated update of session parameters causes an unexpected restart due to a stack overflow.

Affected products

Remediation

Vendor solution

Update to CMU Firmware versions 13.3.3 or 13.4.1.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Hitachi Energy
Published Jul 26, 2023
Updated Mar 5, 2025
Reserved Dec 19, 2022
CISA Vulnrichment
Updated Mar 5, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Hitachi Energy
Published Jul 26, 2023
Updated Mar 5, 2025
Exploited since n/a
EUVD-2022-51940