Input Validation Vulnerability in GOOSE Messages of Hitachi Energy Equipment
CVE-2023-4518

7.5HIGH

Key Information:

Vendor

Hitachi

Status
Vendor
CVE Published:
1 December 2023

What is CVE-2023-4518?

A vulnerability has been identified in the input validation of GOOSE messages used by Hitachi Energy's Intelligent Electronic Devices (IEDs). This vulnerability arises from the handling of out-of-range values, which can lead to unexpected device reboots. Exploitation requires specific configurations of the GOOSE receiving blocks, making it essential for users to assess their system settings and follow recommended security practices to mitigate the risk of potential disruptions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Relion670 Relion 670 series version 2.2.0 all revisions

Relion670 Relion 670 series version 2.2.0 all revisions

Relion670 Relion 670/650/SAM600-IO series version 2.2.1 all revisions

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.