CVE-2022-2277

Improper Input Validation vulnerability exists in the Hitachi Energy MicroSCADA X SYS600's ICCP stack during the ICCP communication establishment causes a denial-of-service when ICCP of SYS600 is request to forward any data item updates with timestamps too distant in the future to any remote ICCP system. By default, ICCP is not configured and not enabled. This issue affects: Hitachi Energy MicroSCADA X SYS600 version 10.2 to version 10.3.1. cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3.1:*:*:*:*:*:*:*
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:hitachienergy:microscada_x_sys600:*:*:*:*:*:*:*:*
cpe:2.3:h:hitachienergy:sys600:-:*:*:*:*:*:*:*

History

25 Sep 2024, 11:15

Type Values Removed Values Added
References
  • {'url': 'https://publisher.hitachienergy.com/preview?DocumentId=8DBD000106&languageCode=en&Preview=true', 'source': 'cybersecurity@hitachienergy.com'}
  • () https://publisher.hitachienergy.com/preview?DocumentID=8DBD000106&LanguageCode=en&DocumentPartId=&Action=Launch -

23 Sep 2024, 13:15

Type Values Removed Values Added
References
  • {'url': 'https://search.abb.com/library/Download.aspx?DocumentID=8DBD000106&LanguageCode=en&DocumentPartId=&Action=Launch', 'tags': ['Vendor Advisory'], 'source': 'cybersecurity@hitachienergy.com'}
  • () https://publisher.hitachienergy.com/preview?DocumentId=8DBD000106&languageCode=en&Preview=true -
CWE CWE-20

21 Jul 2023, 19:26

Type Values Removed Values Added
CWE CWE-20 CWE-1284

Information

Published : 2022-09-14 18:15

Updated : 2024-09-25 11:15


NVD link : CVE-2022-2277

Mitre link : CVE-2022-2277

CVE.ORG link : CVE-2022-2277


JSON object : View

Products Affected

hitachienergy

  • sys600
  • microscada_x_sys600
CWE
CWE-1284

Improper Validation of Specified Quantity in Input