← Back to home
ICSA-23-234-01  ·  Published 2023-08-22  ·  View on CISA ICS-CERT ↗

Hitachi Energy AFF66x

CVSS 9.6 CRITICAL

Risk Summary

Successful exploitation of these vulnerabilities could allow an attacker to compromise availability, integrity, and confidentiality of the targeted devices.

Remediations

  • Hitachi Energy recommends the following actions:
  • Update to upcoming AFF660/665 FW 04.6.01 release when available.
  • Configure only trusted DNS server(s).
  • Configure the NTP service with redundant trustworthy sources of time.
  • Restrict TCP/IP-based management protocols to trusted IP addresses.
  • Disable the SNMP server (CLI and web interface will continue to function as they use an internal connection).
  • Hitachi Energy recommends the following general mitigations:
  • Recommended security practices and firewall configurations could help protect a process control network from attacks originating from outside the network.
  • Physically protect process control systems from direct access by unauthorized personnel.
  • Ensure process control systems have no direct connections to the internet and are separated from other networks via a firewall system with minimal exposed ports.
  • Do not use process control systems for internet surfing, instant messaging, or receiving emails.
  • Scan portable computers and removable storage media for malware prior connection to a control system.
  • For more information, see Hitachi Energy's Security Advisory: 8DBD000167.

Affected Vendors

Hitachi Energy

Affected Products (1)

Hitachi Energy · AFF660/665 <= 03.0.02

Affected Sectors

Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more