CVE-2023-5767
published 2023-12-04CVE-2023-5767: A vulnerability exists in the webserver that affects the RTU500 series product versions listed below. A malicious actor could perform cross-site scripting on…
PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.39%
33.1th percentile
A vulnerability exists in the webserver that affects the
RTU500 series product versions listed below. A malicious
actor could perform cross-site scripting on the webserver
due to an RDT language file being improperly sanitized.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hitachi_energy | rtu500 | — | — |
| hitachi_energy | rtu500 | — | — |
| hitachi_energy | rtu500 | — | — |
| hitachi_energy | rtu500 | — | — |
| hitachi_energy | rtu500 | — | — |
| hitachi_energy | rtu500 | — | — |
| hitachi_energy | rtu500 | — | — |
| hitachienergy | rtu520_firmware | 12.0.1 – 12.0.14 | — |
| hitachienergy | rtu520_firmware | 12.2.1 – 12.2.11 | — |
| hitachienergy | rtu520_firmware | 12.4.1 – 12.4.11 | — |
| hitachienergy | rtu520_firmware | 12.6.1 – 12.6.9 | — |
| hitachienergy | rtu520_firmware | 12.7.1 – 12.7.6 | — |
| hitachienergy | rtu520_firmware | 13.2.1 – 13.2.6 | — |
| hitachienergy | rtu520_firmware | 13.4.1 – 13.4.3 | — |
| hitachienergy | rtu530_firmware | 12.0.1 – 12.0.14 | — |
| hitachienergy | rtu530_firmware | 12.2.1 – 12.2.11 | — |
| hitachienergy | rtu530_firmware | 12.4.1 – 12.4.11 | — |
| hitachienergy | rtu530_firmware | 12.6.1 – 12.6.9 | — |
| hitachienergy | rtu530_firmware | 12.7.1 – 12.7.6 | — |
| hitachienergy | rtu530_firmware | 13.2.1 – 13.2.6 | — |
| hitachienergy | rtu530_firmware | 13.4.1 – 13.4.3 | — |
| hitachienergy | rtu540_firmware | 12.0.1 – 12.0.14 | — |
| hitachienergy | rtu540_firmware | 12.2.1 – 12.2.11 | — |
| hitachienergy | rtu540_firmware | 12.4.1 – 12.4.11 | — |
| hitachienergy | rtu540_firmware | 12.6.1 – 12.6.9 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wr6r-5f4w-8399: A vulnerability exists in the webserver that affects the
RTU500 series product versions listed below
ghsa_unreviewed·2023-12-04
CVE-2023-5767 [MEDIUM] CWE-79 GHSA-wr6r-5f4w-8399: A vulnerability exists in the webserver that affects the
RTU500 series product versions listed below
A vulnerability exists in the webserver that affects the
RTU500 series product versions listed below. A malicious
actor could perform cross-site scripting on the webserver
due to an RDT language file being improperly sanitized.
CISA ICS
Hitachi Energy RTU500 Series
cisa_ics·2025-05-08·CVSS 6.0
[MEDIUM] Hitachi Energy RTU500 Series
ICS Advisory
##
Hitachi Energy RTU500 Series
Release DateMay 08, 2025
Alert CodeICSA-25-128-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.2
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: RTU500 series
- Vulnerabilities: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Validation of Specified Index, Position, or Offset in Input
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to execute cross-site scripting or trigger a denial-of-service condition on the affected device.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Hitachi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-12-04
Published