CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AI Score
Confidence
High
EPSS
Percentile
34.1%
A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-3. After session resumption interval is expired an RTU500 initiated update of session parameters causes an unexpected restart due to a stack overflow.
Vendor | Product | Version | CPE |
---|---|---|---|
hitachienergy | rtu500_firmware | 13.3.1 | cpe:2.3:o:hitachienergy:rtu500_firmware:13.3.1:*:*:*:*:*:*:* |
hitachienergy | rtu500_firmware | 13.3.2 | cpe:2.3:o:hitachienergy:rtu500_firmware:13.3.2:*:*:*:*:*:*:* |
hitachienergy | rtu500_firmware | 13.3.3 | cpe:2.3:o:hitachienergy:rtu500_firmware:13.3.3:*:*:*:*:*:*:* |
hitachienergy | rtu500_firmware | 13.4.1 | cpe:2.3:o:hitachienergy:rtu500_firmware:13.4.1:*:*:*:*:*:*:* |
hitachienergy | rtu500 | - | cpe:2.3:h:hitachienergy:rtu500:-:*:*:*:*:*:*:* |
[
{
"defaultStatus": "unaffected",
"product": "RTU500 series",
"vendor": "Hitachi Energy",
"versions": [
{
"status": "affected",
"version": "RTU500 series CMU Firmware version 13.3.1"
},
{
"status": "affected",
"version": "RTU500 series CMU Firmware version 13.3.2"
},
{
"status": "unaffected",
"version": "RTU500 series CMU Firmware version 13.3.3"
},
{
"status": "unaffected",
"version": "RTU500 series CMU Firmware version 13.4.1"
}
]
}
]