Vulnerability exists in SCI IEC 60870-5-104 and HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Specially crafted messages sent to the mentioned components are not validated properly and can result in buffer overflow and as final consequence to a reboot of an RTU500 CMU.
Existe una vulnerabilidad en SCI IEC 60870-5-104 y HCI IEC 60870-5-104 que afecta a las versiones de productos de RTU500 series que se enumeran a continuación. Los mensajes especialmente manipulados enviados a los componentes mencionados no se validan correctamente y pueden provocar un desbordamiento de búfer y, como consecuencia final, un reinicio de una CMU RTU500.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | NONE |
| Availability Impact | HIGH |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-120
|
| [email protected] | Primary |
en
CWE-120
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| hitachienergy | rtu500_firmware | * | <built-in method update of dict object at 0x72a9ccf2a800> | Operating System |
| hitachienergy | rtu500_firmware | * | <built-in method update of dict object at 0x72a9b0ca4b40> | Operating System |
| hitachienergy | rtu500_firmware | * | <built-in method update of dict object at 0x72a9cc5b2800> | Operating System |
| hitachienergy | rtu500_firmware | * | <built-in method update of dict object at 0x72a9ccf2ab80> | Operating System |
| hitachienergy | rtu500_firmware | * | <built-in method update of dict object at 0x72a9ccf29cc0> | Operating System |
| hitachienergy | rtu500_firmware | * | <built-in method update of dict object at 0x72a9ccf28940> | Operating System |
| hitachienergy | rtu500_firmware | * | <built-in method update of dict object at 0x72a9b0ca61c0> | Operating System |
| hitachienergy | rtu500_firmware | 13.5.1.0 | <built-in method update of dict object at 0x72a9b0ca7b40> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:hitachienergy:rtu500_firmware:13.5.1.0:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:hitachienergy:rtu500:-:*:*:*:*:*:*:* |