CVE-2022-3353: IEC 61850 MMS-Server Vulnerability in multiple Hitachi Energy Products
A vulnerability exists in the IEC 61850 communication stack that affects multiple Hitachi Energy products.
An attacker could exploit the vulnerability by using a specially crafted message sequence, to force the IEC 61850 MMS-server communication stack, to stop accepting new MMS-client connections.
Already existing/established client-server connections are not affected.
List of affected CPEs:
cpe:2.3:o:hitachienergy:fox61xtego1:r15b08::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r2a163::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r2a16::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r1e01::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r1d02::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r1c07::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r1b02::::::: cpe:2.3:a:hitachienergy:gms600:1.3.0::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.1.::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.5.::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.6.0::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.6.0.1::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.7.0::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.7.2::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.8.0::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:2.0.::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:2.1.0.4::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:2.1.0.5::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.2::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.2.1::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.3::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.3.1::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.4::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.4.1::::::: cpe:2.3:a:hitachienergy:mms:2.2.3::::::: cpe:2.3:a:hitachienergy:pwc600:1.0::::::: cpe:2.3:a:hitachienergy:pwc600:1.1::::::: cpe:2.3:a:hitachienergy:pwc600:1.2::::::: cpe:2.3:o:hitachienergy:reb500:7:::::::: cpe:2.3:o:hitachienergy:reb500:8::::::: cpe:2.3:o:hitachienergy:relion670:1.2.::::::: cpe:2.3:o:hitachienergy:relion670:2.0.::::::: cpe:2.3:o:hitachienergy:relion650:1.1.::::::: cpe:2.3:o:hitachienergy:relion650:1.3.::::::: cpe:2.3:o:hitachienergy:relion650:2.1.::::::: cpe:2.3:o:hitachienergy:relion670:2.1.::::::: cpe:2.3:o:hitachienergy:relionSAM600-IO:2.2.1::::::: cpe:2.3:o:hitachienergy:relionSAM600-IO:2.2.5::::::: cpe:2.3:o:hitachienergy:relion670:2.2.::::::: cpe:2.3:o:hitachienergy:relion650:2.2.::::::: cpe:2.3:o:hitachienergy:rtu500cmu:12..::::::: cpe:2.3:a:hitachienergy:rtu500cmu:13..::::::: cpe:2.3:a:hitachienergy:txperthubcoretec4:2.::::::: cpe:2.3:a:hitachienergy:txperthubcoretec4:3.0::::::: cpe:2.3:a:hitachienergy:txperthubcoretec5:3.0:::::::
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3353?
CVE-2022-3353 is classified as a vulnerability that affects multiple Hitachi Energy products, potentially leading to service disruption.
How do I fix CVE-2022-3353?
To fix CVE-2022-3353, you should update the affected Hitachi Energy firmware to the latest available version.
Which products are affected by CVE-2022-3353?
CVE-2022-3353 affects various Hitachi Energy products, including the Sys600, Rtu500, and Pwc600 firmware versions.
What can an attacker do by exploiting CVE-2022-3353?
An attacker exploiting CVE-2022-3353 could send specially crafted message sequences to disrupt the IEC 61850 MMS-server communication stack.
Is there a workaround for CVE-2022-3353?
Currently, there are no documented workarounds for CVE-2022-3353, so applying firmware updates is the recommended action.