Cross-Site Scripting Vulnerability in Hitachi Energy's RTU500 Series
CVE-2023-5767
Summary
A cross-site scripting vulnerability has been identified in the web server of Hitachi Energy's RTU500 series products. This issue arises from improper sanitization of an RDT language file, allowing malicious actors to inject arbitrary JavaScript code. If exploited, this vulnerability could compromise the integrity of web applications hosted on the RTU500 series, potentially leading to unauthorized access and manipulation of sensitive data. Users are advised to review their systems and apply necessary mitigations to secure against these types of attacks.
Affected Version(s)
RTU500 RTU500 series CMU Firmware version 12.0.1 – 12.0.14
RTU500 RTU500 series CMU Firmware version 12.2.1 – 12.2.11
RTU500 RTU500 series CMU Firmware version 12.4.1 – 12.4.11
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved