CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
HIGH
Availability Impact
LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L
EPSS
Percentile
17.0%
A vulnerability exists in the webserver that affects the
RTU500 series product versions listed below. A malicious
actor could perform cross-site scripting on the webserver
due to an RDT language file being improperly sanitized.
[
{
"defaultStatus": "unaffected",
"product": "RTU500",
"vendor": "Hitachi Energy",
"versions": [
{
"status": "affected",
"version": "RTU500 series CMU Firmware version 12.0.1 – 12.0.14"
},
{
"status": "affected",
"version": "RTU500 series CMU Firmware version 12.2.1 – 12.2.11"
},
{
"status": "affected",
"version": "RTU500 series CMU Firmware version 12.4.1 – 12.4.11"
},
{
"status": "affected",
"version": "RTU500 series CMU Firmware version 12.6.1 – 12.6.9"
},
{
"status": "affected",
"version": "RTU500 series CMU Firmware version 12.7.1 – 12.7.6"
},
{
"status": "affected",
"version": "RTU500 series CMU Firmware version 13.2.1 – 13.2.6"
},
{
"status": "affected",
"version": "RTU500 series CMU Firmware version 13.4.1 – 13.4.3"
}
]
}
]