CVE-2021-35533: Specially Crafted IEC 60870-5-104 Packet Vulnerability in RTU500 series
Improper Input Validation vulnerability in the APDU parser in the Bidirectional Communication Interface (BCI) IEC 60870-5-104 function of Hitachi Energy RTU500 series allows an attacker to cause the receiving RTU500 CMU of which the BCI is enabled to reboot when receiving a specially crafted message. By default, BCI IEC 60870-5-104 function is disabled (not configured). This issue affects: Hitachi Energy RTU500 series CMU Firmware version 12.0. (all versions); CMU Firmware version 12.2. (all versions); CMU Firmware version 12.4. (all versions).
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2021-35533.
What is the severity of CVE-2021-35533?
The severity of CVE-2021-35533 is high with a severity value of 7.5.
Which software versions are affected by CVE-2021-35533?
The affected software versions are 12.0, 12.2, and 12.4 of Hitachi Energy RTU500 firmware.
How does CVE-2021-35533 affect Hitachi Energy RTU500 CMU?
CVE-2021-35533 allows an attacker to cause the receiving RTU500 CMU to reboot when receiving a specially crafted message.
How can I fix CVE-2021-35533?
To fix CVE-2021-35533, update the Hitachi Energy RTU500 firmware to a version that is not vulnerable.