CVE-2022-2081: High severity hitachi energy rtu520 vulnerability
A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is enabled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500 in a high rate, causing the targeted RTU500 CMU to reboot. The vulnerability is caused by a lack of flood control which eventually if exploited causes an internal stack overflow in the HCI Modbus TCP function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2081?
CVE-2022-2081 has been assigned a severity rating that depends on the potential impact of an attack exploiting the vulnerability.
How do I fix CVE-2022-2081?
To fix CVE-2022-2081, ensure that the HCI Modbus TCP function is disabled if not in use, and update to the latest firmware version provided by Hitachi Energy.
Which versions of firmware are affected by CVE-2022-2081?
CVE-2022-2081 affects Hitachi Energy RTU520, RTU530, RTU540, and RTU560 firmware versions within specific ranges as listed for each model.
What kind of attack can exploit CVE-2022-2081?
An attacker can exploit CVE-2022-2081 by sending specially crafted messages at a high rate to the affected RTU500 devices.
Is there a workaround for CVE-2022-2081?
A potential workaround for CVE-2022-2081 is to configure settings to minimize exposure, such as restricting network access to the HCI Modbus TCP function.