CVE-2022-3353: IEC 61850 MMS-Server Vulnerability in multiple Hitachi Energy Products

Published Feb 21, 2023
·
Updated

A vulnerability exists in the IEC 61850 communication stack that affects multiple Hitachi Energy products.

An attacker could exploit the vulnerability by using a specially crafted message sequence, to force the IEC 61850 MMS-server communication stack, to stop accepting new MMS-client connections.

Already existing/established client-server connections are not affected.

List of affected CPEs:

cpe:2.3:o:hitachienergy:fox61xtego1:r15b08::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r2a163::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r2a16::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r1e01::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r1d02::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r1c07::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r1b02::::::: cpe:2.3:a:hitachienergy:gms600:1.3.0::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.1.::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.5.::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.6.0::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.6.0.1::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.7.0::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.7.2::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.8.0::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:2.0.::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:2.1.0.4::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:2.1.0.5::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.2::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.2.1::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.3::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.3.1::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.4::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.4.1::::::: cpe:2.3:a:hitachienergy:mms:2.2.3::::::: cpe:2.3:a:hitachienergy:pwc600:1.0::::::: cpe:2.3:a:hitachienergy:pwc600:1.1::::::: cpe:2.3:a:hitachienergy:pwc600:1.2::::::: cpe:2.3:o:hitachienergy:reb500:7:::::::: cpe:2.3:o:hitachienergy:reb500:8::::::: cpe:2.3:o:hitachienergy:relion670:1.2.::::::: cpe:2.3:o:hitachienergy:relion670:2.0.::::::: cpe:2.3:o:hitachienergy:relion650:1.1.::::::: cpe:2.3:o:hitachienergy:relion650:1.3.::::::: cpe:2.3:o:hitachienergy:relion650:2.1.::::::: cpe:2.3:o:hitachienergy:relion670:2.1.::::::: cpe:2.3:o:hitachienergy:relionSAM600-IO:2.2.1::::::: cpe:2.3:o:hitachienergy:relionSAM600-IO:2.2.5::::::: cpe:2.3:o:hitachienergy:relion670:2.2.::::::: cpe:2.3:o:hitachienergy:relion650:2.2.::::::: cpe:2.3:o:hitachienergy:rtu500cmu:12..::::::: cpe:2.3:a:hitachienergy:rtu500cmu:13..::::::: cpe:2.3:a:hitachienergy:txperthubcoretec4:2.::::::: cpe:2.3:a:hitachienergy:txperthubcoretec4:3.0::::::: cpe:2.3:a:hitachienergy:txperthubcoretec5:3.0:::::::

Affected Software

74 affected components
hitachienergy Sys600 Firmware>=10.1<=10.3.1
hitachienergy SYS600
hitachienergy Rtu500 Firmware>=12.0.1.0<=12.0.14.0
hitachienergy Rtu500 Firmware>=12.2.1.0<=12.2.11.0
hitachienergy Rtu500 Firmware>=12.4.1.0<=12.4.11.0
hitachienergy Rtu500 Firmware>=12.6.1.0<=12.6.8.0
hitachienergy Rtu500 Firmware>=12.7.1.0<=12.7.4.0
hitachienergy Rtu500 Firmware>=13.2.1.0<=13.2.5.0
hitachienergy Rtu500 Firmware>=13.3.1<=13.3.3
hitachienergy Rtu500 Firmware=13.4.1
hitachienergy rtu500
hitachienergy Reb500 Firmware>=7.0<8.3.3
hitachienergy reb500
hitachienergy Pwc600 Firmware=1.0
hitachienergy Pwc600 Firmware=1.1
hitachienergy Pwc600 Firmware=1.2
hitachienergy pwc600
hitachienergy Modular Switchgear Monitoring Firmware<=2.2.3
hitachienergy Modular Switchgear Monitoring
hitachienergy Itt600 Sa Explorer=1.1.0
hitachienergy Itt600 Sa Explorer=1.1.1
hitachienergy Itt600 Sa Explorer=1.1.2
hitachienergy Itt600 Sa Explorer=1.5.0
hitachienergy Itt600 Sa Explorer=1.5.1
hitachienergy Itt600 Sa Explorer=1.6.0
hitachienergy Itt600 Sa Explorer=1.6.0.1
hitachienergy Itt600 Sa Explorer=1.7.0
hitachienergy Itt600 Sa Explorer=1.7.2
hitachienergy Itt600 Sa Explorer=1.8.0
hitachienergy Itt600 Sa Explorer=2.0.1
hitachienergy Itt600 Sa Explorer=2.0.2
hitachienergy Itt600 Sa Explorer=2.0.3
hitachienergy Itt600 Sa Explorer=2.0.4.1
hitachienergy Itt600 Sa Explorer=2.0.5.0
hitachienergy Itt600 Sa Explorer=2.0.5.4
hitachienergy Itt600 Sa Explorer=2.1.0.4
hitachienergy Itt600 Sa Explorer=2.1.0.5
hitachienergy Relion Sam600-io Firmware=2.2.1
hitachienergy Relion Sam600-io Firmware=2.2.5
hitachienergy Relion Sam600-io
hitachienergy Relion 650 Firmware=1.1
hitachienergy Relion 650 Firmware=1.3
hitachienergy Relion 650 Firmware=2.1
hitachienergy Relion 650 Firmware=2.2.0
hitachienergy Relion 650 Firmware=2.2.1
hitachienergy Relion 650 Firmware=2.2.2
hitachienergy Relion 650 Firmware=2.2.3
hitachienergy Relion 650 Firmware=2.2.4
hitachienergy Relion 650 Firmware=2.2.5
hitachienergy Relion 650
hitachienergy Relion 670 Firmware=1.2
hitachienergy Relion 670 Firmware=2.0
hitachienergy Relion 670 Firmware=2.1
hitachienergy Relion 670 Firmware=2.2.0
hitachienergy Relion 670 Firmware=2.2.1
hitachienergy Relion 670 Firmware=2.2.2
hitachienergy Relion 670 Firmware=2.2.3
hitachienergy Relion 670 Firmware=2.2.4
hitachienergy Relion 670 Firmware=2.2.5
hitachienergy Relion 670
hitachienergy Gms600 Firmware=1.3.0
hitachienergy gms600
hitachienergy Fox615 Tego1 Firmware=r1b02
hitachienergy Fox615 Tego1 Firmware=r1c07
hitachienergy Fox615 Tego1 Firmware=r1d02
hitachienergy Fox615 Tego1 Firmware=r1e01
hitachienergy Fox615 Tego1 Firmware=r2b16
hitachienergy Fox615 Tego1 Firmware=r2b16_03
hitachienergy Fox615 Tego1 Firmware=r15b08
hitachienergy Fox615 Tego1
hitachienergy Txpert Hub Coretec 4 Firmware>=2.0.0<=3.0.0
hitachienergy Txpert Hub Coretec 4
hitachienergy Txpert Hub Coretec 5 Firmware=3.0.0
hitachienergy Txpert Hub Coretec 5

Remediation

Information

Upgrade the system once remediated version is available.

Event History

Feb 21, 2023
CVE Published
via MITRE·01:50 PM
Data Sourced
via MITRE·01:50 PM
RemedyDescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2022-3353?

CVE-2022-3353 is classified as a vulnerability that affects multiple Hitachi Energy products, potentially leading to service disruption.

2

How do I fix CVE-2022-3353?

To fix CVE-2022-3353, you should update the affected Hitachi Energy firmware to the latest available version.

3

Which products are affected by CVE-2022-3353?

CVE-2022-3353 affects various Hitachi Energy products, including the Sys600, Rtu500, and Pwc600 firmware versions.

4

What can an attacker do by exploiting CVE-2022-3353?

An attacker exploiting CVE-2022-3353 could send specially crafted message sequences to disrupt the IEC 61850 MMS-server communication stack.

5

Is there a workaround for CVE-2022-3353?

Currently, there are no documented workarounds for CVE-2022-3353, so applying firmware updates is the recommended action.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203