← Back to home
ICSA-22-235-07  ·  Published 2022-08-23  ·  View on CISA ICS-CERT ↗

Hitachi Energy RTU500

CVSS 7.5 HIGH

Risk Summary

Successful exploitation of this vulnerability could allow an attacker to send a specially crafted Modbus TCP packet in a high rate, causing a stack overflow, which could result in a reboot of the product.

CVEs (1)

Remediations

  • Update to RTU500 series CMU Firmware version 12.0.14.0 or higher.
  • Update to RTU500 series CMU Firmware version 12.2.12.0 or higher.
  • Update to RTU500 series CMU Firmware version 12.4.12.0 or higher.
  • Update to RTU500 series CMU Firmware version 12.6.8.0 or higher.
  • Update to RTU500 series CMU Firmware version 12.7.4.0 or higher.
  • Update to RTU500 series CMU Firmware version 13.2.5.0 or higher.
  • Update to RTU500 series CMU Firmware version 13.3.2.0 or higher.
  • Users should see Hitachi Energy advisory 8DBD000111 for additional mitigation and update information.

Affected Vendors

Hitachi Energy

Affected Products (7)

Hitachi Energy · RTU500 series CMU 12.4.1-12.4.11
Hitachi Energy · RTU500 series CMU 12.7.1-12.7.3
Hitachi Energy · RTU500 series CMU 12.6.1-12.6.7
Hitachi Energy · RTU500 series CMU 13.2.1-13.2.4
Hitachi Energy · RTU500 series CMU 13.3.1
Hitachi Energy · RTU500 series CMU 12.2.1-12.2.11
Hitachi Energy · RTU500 series CMU 12.0.1-12.0.13

Affected Sectors

Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more