CVE-2022-4608
published 2023-07-26CVE-2022-4608: A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.71%
52.2th percentile
A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-3. After session resumption interval is expired an RTU500 initiated update of session parameters causes an unexpected restart due to a stack overflow.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hitachi_energy | rtu500_series | — | — |
| hitachi_energy | rtu500_series | — | — |
| hitachienergy | rtu500_firmware | — | — |
| hitachienergy | rtu500_firmware | — | — |
| hitachienergy | rtu500_firmware | — | — |
| hitachienergy | rtu500_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5568-g9wp-2cv7: A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product
ghsa_unreviewed·2023-07-26
CVE-2022-4608 [HIGH] CWE-120 GHSA-5568-g9wp-2cv7: A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product
A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-3. After session resumption interval is expired an RTU500 initiated update of session parameters causes an unexpected restart due to a stack overflow.
CISA ICS
Hitachi Energy RTU500 series
cisa_ics·2023-08-08·CVSS 7.5
[HIGH] Hitachi Energy RTU500 series
ICS Advisory
##
Hitachi Energy RTU500 series
Release DateAugust 08, 2023
Alert CodeICSA-23-220-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: RTU500 series
- Vulnerabilities: Stack-based Buffer Overflow
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could cause a buffer overflow and reboot of the product.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Hitachi Energy reports these vulnerabilities affect the following RTU500 series products:
- RTU500 series CMU: Firmware versions 13.3.1–13.3.2
## 3.2 VULNERABILITY OVERVIEW
3.2.1 STACK-BASED BUFFER OVERFLOW CWE-121
A vulnerability exists in the HCI IEC 60870-5-104 function included
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-26
Published