HIGH
A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product
Published Jul 26, 2023
7.5
HIGHCVSS 3.1
EPSS 0.71%
Description
A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-3. After session resumption interval is expired an RTU500 initiated update of session parameters causes an unexpected restart due to a stack overflow.
Affected products
-
- Version RTU500 series CMU Firmware version 13.3.1StatusaffectedConstraints-
- Version RTU500 series CMU Firmware version 13.3.2StatusaffectedConstraints-
- Version RTU500 series CMU Firmware version 13.3.3StatusunaffectedConstraints-
- Version RTU500 series CMU Firmware version 13.4.1StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Hitachi Energy | RTU500 series | unaffected |
|
AND
OR
- 13.3.1
- 13.3.2
- 13.3.3
- 13.4.1
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update to CMU Firmware versions 13.3.3 or 13.4.1.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-51940 Advisory
- https://publisher.hitachienergy.com/preview?DocumentID=8DBD000121&LanguageCode=en&DocumentPartId=&Action=Launch vendor-advisory
- https://search.abb.com/library/Download.aspx?DocumentID=8DBD000121&LanguageCode=en&DocumentPartId=&Action=Launch
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Hitachi Energy
Published Jul 26, 2023
Updated Mar 5, 2025
Reserved Dec 19, 2022
Link CVE-2022-4608
CISA Vulnrichment
Updated Mar 5, 2025
ENISA EUVD
EUVD-2022-51940 Assigner Hitachi Energy
Published Jul 26, 2023
Updated Mar 5, 2025
Exploited since n/a
Link EUVD-2022-51940