First published: Wed Sep 14 2022(Updated: )
Improper Input Validation vulnerability in the handling of a specially crafted IEC 61850 packet with a valid data item but with incorrect data type in the IEC 61850 OPC Server in the Hitachi Energy MicroSCADA X SYS600, MicroSCADA Pro SYS600. The vulnerability may cause a denial-of-service on the IEC 61850 OPC Server part of the SYS600 product. This issue affects: Hitachi Energy MicroSCADA Pro SYS600 version 9.4 FP2 Hotfix 4 and earlier versions Hitachi Energy MicroSCADA X SYS600 version 10 to version 10.3.1. cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.0:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.2:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.3:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.1.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3.1:*:*:*:*:*:*:*
Credit: cybersecurity@hitachienergy.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachienergy Microscada X Sys600 | >=9.0<10.4 | |
Hitachienergy Sys600 |
Remediated in SYS600 10.4 For MicroSCADA Pro SYS600 - Upgrade to at least SYS600 version 10.4. For MicroSCADA X SYS600 - Update to at least SYS600 version 10.4.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29922 is an Improper Input Validation vulnerability found in the handling of a specially crafted IEC 61850 packet in the Hitachi Energy MicroSCADA X SYS600 and MicroSCADA Pro SYS600.
CVE-2022-29922 can cause a denial-of-service (DoS) on the IEC 61850 OPC Server in the Hitachi Energy MicroSCADA X SYS600 and MicroSCADA Pro SYS600.
CVE-2022-29922 has a severity rating of 7.5 (High).
To fix CVE-2022-29922, it is recommended to apply the necessary patches or updates provided by Hitachi Energy for the MicroSCADA X SYS600 and MicroSCADA Pro SYS600.
You can find more information about CVE-2022-29922 in the reference link provided: [https://search.abb.com/library/Download.aspx?DocumentID=8DBD000106&LanguageCode=en&DocumentPartId=&Action=Launch]