Vulnerability exists in SCI IEC 60870-5-104 and HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Specially crafted messages sent to the mentioned components are not validated properly and can result in buffer overflow and as final consequence to a reboot of an RTU500 CMU.
References
Link | Resource |
---|---|
https://publisher.hitachienergy.com/preview?DocumentId=8DBD000184&languageCode=en&Preview=true | Vendor Advisory |
https://publisher.hitachienergy.com/preview?DocumentId=8DBD000184&languageCode=en&Preview=true | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 08:44
Type | Values Removed | Values Added |
---|---|---|
References | () https://publisher.hitachienergy.com/preview?DocumentId=8DBD000184&languageCode=en&Preview=true - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.9 |
25 Sep 2024, 09:15
Type | Values Removed | Values Added |
---|---|---|
CWE |
28 Dec 2023, 19:03
Type | Values Removed | Values Added |
---|---|---|
First Time |
Hitachienergy rtu500 Firmware
Hitachienergy rtu500 Hitachienergy |
|
References | () https://publisher.hitachienergy.com/preview?DocumentId=8DBD000184&languageCode=en&Preview=true - Vendor Advisory | |
CWE | CWE-120 | |
CPE | cpe:2.3:o:hitachienergy:rtu500_firmware:13.5.1.0:*:*:*:*:*:*:* cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:hitachienergy:rtu500:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
19 Dec 2023, 16:17
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-19 15:15
Updated : 2024-11-21 08:44
NVD link : CVE-2023-6711
Mitre link : CVE-2023-6711
CVE.ORG link : CVE-2023-6711
JSON object : View
Products Affected
hitachienergy
- rtu500_firmware
- rtu500
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')