QID 591424

QID 591424: Hitachi Energy RTU500 series Stack-based Buffer Overflow Vulnerability (8DBD000121,ICSA-23-220-02)

AFFECTED PRODUCTS
A vulnerability exists in the HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited if the HCI 60870-5-104 is configured with IEC 62351-5 and IEC 62351-3 support:
RTU500 series CMU: Firmware versions 13.3.1-13.3.2

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version using passive scanning.

Successful exploitation of these vulnerabilities could cause a buffer overflow and reboot of the product.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Hitachi Energy recommends users update to CMU Firmware versions 13.3.3 or 13.4.1.

    Customers are advised to refer to CERT MITIGATIONS section ICSA-23-220-02 for affected packages and patching details.Workaround:
    The reported vulnerabilities affect only the RTU500 series with HCI IEC 60870-5-104 and IEC62351-5 or IEC 62351-5 configured and enable. A possible mitigation is to disable the HCI IEC 60870-5-104 function or its IEC 62351-3 and IEC 62351-5 features if they are not used. NOTE: By default, the HCI IEC 60870-5-104, as well as its IEC 62351-3 or IEC 62351-5 support are disabled.

    CVEs related to QID 591424

    Software Advisories
    Advisory ID Software Component Link
    ICSA-23-220-02 URL Logo www.cisa.gov/news-events/ics-advisories/icsa-23-220-02