IM
IronMonkey Threat Research

CVE-2023-6711 HIGH

Published: 2023-12-19 | Last Modified: 2024-11-21 | Status: Modified

Description

Vulnerability exists in SCI IEC 60870-5-104 and HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Specially crafted messages sent to the mentioned components are not validated properly and can result in buffer overflow and as final consequence to a reboot of an RTU500 CMU.

Additional Descriptions (1)

Existe una vulnerabilidad en SCI IEC 60870-5-104 y HCI IEC 60870-5-104 que afecta a las versiones de productos de RTU500 series que se enumeran a continuación. Los mensajes especialmente manipulados enviados a los componentes mencionados no se validan correctamente y pueden provocar un desbordamiento de búfer y, como consecuencia final, un reinicio de una CMU RTU500.

CVSS Metrics

Base Score: 7.5 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-120
[email protected] Primary
en CWE-120

Affected Products

Vendor Product Version Update Type
hitachienergy rtu500_firmware * <built-in method update of dict object at 0x72a9ccf2a800> Operating System
hitachienergy rtu500_firmware * <built-in method update of dict object at 0x72a9b0ca4b40> Operating System
hitachienergy rtu500_firmware * <built-in method update of dict object at 0x72a9cc5b2800> Operating System
hitachienergy rtu500_firmware * <built-in method update of dict object at 0x72a9ccf2ab80> Operating System
hitachienergy rtu500_firmware * <built-in method update of dict object at 0x72a9ccf29cc0> Operating System
hitachienergy rtu500_firmware * <built-in method update of dict object at 0x72a9ccf28940> Operating System
hitachienergy rtu500_firmware * <built-in method update of dict object at 0x72a9b0ca61c0> Operating System
hitachienergy rtu500_firmware 13.5.1.0 <built-in method update of dict object at 0x72a9b0ca7b40> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:hitachienergy:rtu500_firmware:13.5.1.0:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:hitachienergy:rtu500:-:*:*:*:*:*:*:*
Notification
Message here