QID 591424
QID 591424: Hitachi Energy RTU500 series Stack-based Buffer Overflow Vulnerability (8DBD000121,ICSA-23-220-02)
AFFECTED PRODUCTS
A vulnerability exists in the HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited if the HCI 60870-5-104 is configured with IEC 62351-5 and IEC 62351-3 support:
RTU500 series CMU: Firmware versions 13.3.1-13.3.2
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version using passive scanning.
Successful exploitation of these vulnerabilities could cause a buffer overflow and reboot of the product.
Customers are advised to refer to CERT MITIGATIONS section ICSA-23-220-02 for affected packages and patching details.Workaround:
The reported vulnerabilities affect only the RTU500 series with HCI IEC 60870-5-104 and IEC62351-5 or IEC
62351-5 configured and enable. A possible mitigation is to disable the HCI IEC 60870-5-104 function or its IEC
62351-3 and IEC 62351-5 features if they are not used.
NOTE: By default, the HCI IEC 60870-5-104, as well as its IEC 62351-3 or IEC 62351-5 support are disabled.
- 8DBD000121 -
search.abb.com/library/Download.aspx?DocumentID=8DBD000121 - ICSA-23-220-02 -
www.cisa.gov/news-events/ics-advisories/icsa-23-220-02
CVEs related to QID 591424
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-23-220-02 |
|