Communication Blocking Vulnerability in Hitachi Energy's RTU500 Series
CVE-2023-5768

6.1MEDIUM

Key Information:

Vendor
Hitachi
Vendor
CVE Published:
4 December 2023

Summary

A vulnerability in the HCI IEC 60870-5-104 protocol affects Hitachi Energy's RTU500 series, where improper handling of APDU frame layouts can lead to communication link blockage. Specifically, erroneous or delayed reception of APDU frames can result in an endless blocking state within the link layer. This scenario impairs the communication functionality but is temporarily resolved once the attack sequence ceases, restoring normal link operations.

Affected Version(s)

RTU500 series RTU500 series CMU Firmware version 12.0.1 – 12.0.14

RTU500 series RTU500 series CMU Firmware version 12.2.1 – 12.2.11

RTU500 series RTU500 series CMU Firmware version 12.4.1 – 12.4.11

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.