CVE-2022-4608
Published: Jul 26, 2023
Modified: Mar 5, 2025
CVSS v3.1
7.5
Description
A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-3. After session resumption interval is expired an RTU500 initiated update of session parameters causes an unexpected restart due to a stack overflow.
| Vendor | Product | Versions |
|---|---|---|
Hitachi Energy | RTU500 series | affected RTU500 series CMU Firmware version 13.3.1affected RTU500 series CMU Firmware version 13.3.2unaffected RTU500 series CMU Firmware version 13.3.3unaffected RTU500 series CMU Firmware version 13.4.1 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now