ICSA-23-234-01
·
Published 2023-08-22
·
View on CISA ICS-CERT ↗
Hitachi Energy AFF66x
CVSS 9.6
CRITICAL
Risk Summary
Successful exploitation of these vulnerabilities could allow an attacker to compromise availability, integrity, and confidentiality of the targeted devices.
Remediations
- Hitachi Energy recommends the following actions:
- Update to upcoming AFF660/665 FW 04.6.01 release when available.
- Configure only trusted DNS server(s).
- Configure the NTP service with redundant trustworthy sources of time.
- Restrict TCP/IP-based management protocols to trusted IP addresses.
- Disable the SNMP server (CLI and web interface will continue to function as they use an internal connection).
- Hitachi Energy recommends the following general mitigations:
- Recommended security practices and firewall configurations could help protect a process control network from attacks originating from outside the network.
- Physically protect process control systems from direct access by unauthorized personnel.
- Ensure process control systems have no direct connections to the internet and are separated from other networks via a firewall system with minimal exposed ports.
- Do not use process control systems for internet surfing, instant messaging, or receiving emails.
- Scan portable computers and removable storage media for malware prior connection to a control system.
- For more information, see Hitachi Energy's Security Advisory: 8DBD000167.
Affected Vendors
Hitachi Energy
Affected Products (1)
Hitachi Energy
·
AFF660/665
<= 03.0.02
Affected Sectors
Energy
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more