cbcvebase.
CVE-2022-4608
published 2023-07-26

CVE-2022-4608: A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if…

PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.71%
52.2th percentile
A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-3. After session resumption interval is expired an RTU500 initiated update of session parameters causes an unexpected restart due to a stack overflow.

Affected

6 ranges
VendorProductVersion rangeFixed in
hitachi_energyrtu500_series——
hitachi_energyrtu500_series——
hitachienergyrtu500_firmware——
hitachienergyrtu500_firmware——
hitachienergyrtu500_firmware——
hitachienergyrtu500_firmware——
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.