6.8 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
0.0004 Low
EPSS
Percentile
9.0%
A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could enforce diagnostic texts being displayed as empty strings, if an authorized user uploads a specially crafted stb-language file.
[
{
"defaultStatus": "unaffected",
"product": "RTU500 series CMU firmware",
"vendor": "Hitachi Energy",
"versions": [
{
"lessThanOrEqual": "12.0.14",
"status": "affected",
"version": "12.0.1",
"versionType": "custom"
},
{
"lessThanOrEqual": "12.2.11",
"status": "affected",
"version": "12.2.1",
"versionType": "custom"
},
{
"lessThanOrEqual": "12.4.11",
"status": "affected",
"version": "12.4.1",
"versionType": "custom"
},
{
"lessThanOrEqual": "12.6.9",
"status": "affected",
"version": "12.6.1",
"versionType": "custom"
},
{
"lessThanOrEqual": "12.7.6",
"status": "affected",
"version": "12.7.1",
"versionType": "custom"
},
{
"lessThanOrEqual": "13.2.6",
"status": "affected",
"version": "13.2.1",
"versionType": "custom"
},
{
"lessThanOrEqual": "13.4.4",
"status": "affected",
"version": "13.4.1",
"versionType": "custom"
},
{
"lessThanOrEqual": "13.5.3",
"status": "affected",
"version": "13.5.1",
"versionType": "custom"
}
]
}
]