CVE-2022-2502
published 2023-07-26CVE-2022-2502: A vulnerability exists in the HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.65%
49.2th percentile
A vulnerability exists in the HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-5 and the CMU contains the license feature ‘Advanced security’ which must be ordered separately. If these preconditions are fulfilled, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500, causing the targeted RTU500 CMU to reboot. The vulnerability is caused by a missing input data validation which eventually if exploited causes an internal buffer to overflow in the HCI IEC 60870-5-104 function.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hitachi_energy | rtu500_series | — | — |
| hitachi_energy | rtu500_series | — | — |
| hitachienergy | rtu500_firmware | — | — |
| hitachienergy | rtu500_firmware | — | — |
| hitachienergy | rtu500_firmware | — | — |
| hitachienergy | rtu500_firmware | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cisa8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-45rh-q5fv-wf42: A vulnerability exists in the HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product
ghsa_unreviewed·2023-07-26
CVE-2022-2502 [HIGH] CWE-120 GHSA-45rh-q5fv-wf42: A vulnerability exists in the HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product
A vulnerability exists in the HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-5 and the CMU contains the license feature ‘Advanced security’ which must be ordered separately. If these preconditions are fulfilled, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500, causing the targeted RTU500 CMU to reboot. The vulnerability is caused by a missing input data validation which eventually if exploited causes an internal buffer to overflow in the HCI IEC 60870-5-104 function.
CISA ICS
Hitachi Energy RTU500 series
cisa_ics·2023-08-08·CVSS 7.5
[HIGH] Hitachi Energy RTU500 series
ICS Advisory
##
Hitachi Energy RTU500 series
Release DateAugust 08, 2023
Alert CodeICSA-23-220-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: RTU500 series
- Vulnerabilities: Stack-based Buffer Overflow
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could cause a buffer overflow and reboot of the product.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Hitachi Energy reports these vulnerabilities affect the following RTU500 series products:
- RTU500 series CMU: Firmware versions 13.3.1–13.3.2
## 3.2 VULNERABILITY OVERVIEW
3.2.1 STACK-BASED BUFFER OVERFLOW CWE-121
A vulnerability exists in the HCI IEC 60870-5-104 function included
CISA
Microsoft Internet Explorer Memory Corruption Vulnerability
cisa·2022-04-13·CVSS 8.8
CVE-2015-2502 [HIGH] CWE-119 Microsoft Internet Explorer Memory Corruption Vulnerability
Vulnerability: Microsoft Internet Explorer Memory Corruption Vulnerability
Affected: Microsoft Internet Explorer
Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS).
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-2502
Remediation Due Date: 2022-05-04
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-26
Published