CVE-2024-1532
published 2024-03-27CVE-2024-1532: A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could enforce…
PriorityP431medium6.8CVSS 3.1
AVNACLPRHUINSCCNINAH
EPSS
0.57%
45.8th percentile
A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could enforce diagnostic texts being displayed as empty strings, if an authorized user uploads a specially crafted stb-language file.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hitachi_energy | rtu500_series_cmu_firmware | 12.0.1 – 12.0.14 | — |
| hitachi_energy | rtu500_series_cmu_firmware | 12.2.1 – 12.2.11 | — |
| hitachi_energy | rtu500_series_cmu_firmware | 12.4.1 – 12.4.11 | — |
| hitachi_energy | rtu500_series_cmu_firmware | 12.6.1 – 12.6.9 | — |
| hitachi_energy | rtu500_series_cmu_firmware | 12.7.1 – 12.7.6 | — |
| hitachi_energy | rtu500_series_cmu_firmware | 13.2.1 – 13.2.6 | — |
| hitachi_energy | rtu500_series_cmu_firmware | 13.4.1 – 13.4.4 | — |
| hitachi_energy | rtu500_series_cmu_firmware | 13.5.1 – 13.5.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wwgw-w5hw-vm65: A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below
ghsa_unreviewed·2024-03-27
CVE-2024-1532 [MEDIUM] CWE-434 GHSA-wwgw-w5hw-vm65: A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below
A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could enforce diagnostic texts being displayed as empty strings, if an authorized user uploads a specially crafted stb-language file.
CISA ICS
Multiple Vulnerabilities in Hitachi Energy RTU500 Series
cisa_ics·2024-04-25·CVSS 8.2
[HIGH] Multiple Vulnerabilities in Hitachi Energy RTU500 Series
ICS Advisory
##
Multiple Vulnerabilities in Hitachi Energy RTU500 Series
Release DateApril 25, 2024
Alert CodeICSA-24-116-01
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 7.0
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: RTU500 Series
- Vulnerabilities: Unrestricted Upload of File with Dangerous Type
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Hitachi's RTU500 series CMU Firmware are affected:
- RTU500 series CMU Firmware: Version 12.0.1 - 12.0.14
- RTU500 series CMU
Suricata
GPL WEB_SERVER Tomcat server snoop access
suricata·2010-09-23
CVE-2000-0760 GPL WEB_SERVER Tomcat server snoop access
GPL WEB_SERVER Tomcat server snoop access
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"GPL WEB_SERVER Tomcat server snoop access"; flow:established,to_server; http.uri; content:"/jsp/snp/"; content:".snp"; reference:bugtraq,1532; reference:cve,2000-0760; classtype:attempted-recon; sid:2101108; rev:15; metadata:created_at 2010_09_23, cve CVE_2000_0760, signature_severity Unknown, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
No public exploits indexed.
No writeups or analysis indexed.
2024-03-27
Published