← Back to home
ICSA-23-059-01  ·  Published 2023-03-06  ·  View on CISA ICS-CERT ↗

Hitachi Energy Gateway Station

CVSS 7.5 HIGH

Risk Summary

Successful exploitation of these vulnerabilities could cause affected modules to stop working.

Remediations

  • Hitachi Energy has created an update to address the reported vulnerabilities and recommends users update to at least GWS version 3.3.0.0
  • For CVE-2020-25692, the vulnerability impacts GWS if the authentication service is installed. It is not installed by default but is required during the installation process of GWS or installed manually later. Authentication Service (previously ABB Authentication Service) is only needed when GWS users are authenticated using centralized SDM600 user account management.
  • Hitachi Energy recommends the following general mitigation factors and security practices:
  • Configure firewalls to protect process control networks from attacks originating from outside the network
  • Physically protect process control systems from direct access by unauthorized personnel
  • Avoid directly connecting control systems to the internet
  • Separate process control networks from other networks using a firewall system with a minimal number of ports exposed
  • Process control systems should not be used for internet surfing, instant messaging, or receiving emails
  • Portable computers and removable storage media should be carefully scanned for viruses before connecting to a control system
  • Enforce proper password policies and processes
  • For more information, see Hitachi security advisory 8DBD000118.

Affected Vendors

Hitachi Energy

Affected Products (8)

Hitachi Energy · Gateway Station (GWS) 2.0.0.0
Hitachi Energy · Gateway Station (GWS) 2.1.0.0
Hitachi Energy · Gateway Station (GWS) 2.2.0.0
Hitachi Energy · Gateway Station (GWS) 2.3.0.0
Hitachi Energy · Gateway Station (GWS) 2.4.0.0
Hitachi Energy · Gateway Station (GWS) 3.0.0.0
Hitachi Energy · Gateway Station (GWS) 3.1.0.0
Hitachi Energy · Gateway Station (GWS) <= 3.2.0.0

Affected Sectors

Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more