Buffer Overflow in RTU500 Series by Hitachi Energy
CVE-2022-2502

7.5HIGH

Key Information:

Vendor
Hitachi
Vendor
CVE Published:
26 July 2023

Summary

A buffer overflow vulnerability exists in the HCI IEC 60870-5-104 functionality within certain RTU500 series devices. This vulnerability arises when the HCI is configured to support IEC 62351-5, and the CMU is equipped with the ‘Advanced security’ license. If these conditions are met, an attacker could exploit the vulnerability by sending crafted messages to the RTU500, potentially leading to a restart of the RTU500 CMU. The underlying cause is a lack of input data validation which can result in an internal buffer overflow.

Affected Version(s)

RTU500 series RTU500 series CMU Firmware version 13.3.1

RTU500 series RTU500 series CMU Firmware version 13.3.2

RTU500 series RTU500 series CMU Firmware version 13.3.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.