7.5
CWE
404
Advisory Published
Updated

CVE-2022-3353: IEC 61850 MMS-Server Vulnerability in multiple Hitachi Energy Products

First published: Tue Feb 21 2023(Updated: )

A vulnerability exists in the IEC 61850 communication stack that affects multiple Hitachi Energy products.  An attacker could exploit the vulnerability by using a specially crafted message sequence, to force the IEC 61850 MMS-server communication stack, to stop accepting new MMS-client connections.  Already existing/established client-server connections are not affected. List of affected CPEs: * cpe:2.3:o:hitachienergy:fox61x_tego1:r15b08:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:fox61x_tego1:r2a16_3:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:fox61x_tego1:r2a16:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:fox61x_tego1:r1e01:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:fox61x_tego1:r1d02:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:fox61x_tego1:r1c07:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:fox61x_tego1:r1b02:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:gms600:1.3.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:itt600_sa_explorer:1.1.*:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:itt600_sa_explorer:1.5.*:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:itt600_sa_explorer:1.6.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:itt600_sa_explorer:1.6.0.1:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:itt600_sa_explorer:1.7.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:itt600_sa_explorer:1.7.2:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:itt600_sa_explorer:1.8.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:itt600_sa_explorer:2.0.*:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:itt600_sa_explorer:2.1.0.4:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:itt600_sa_explorer:2.1.0.5:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:microscada_x_sys600:10:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:microscada_x_sys600:10.*:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2.1:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3.1:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:microscada_x_sys600:10.4:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:microscada_x_sys600:10.4.1:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:mms:2.2.3:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:pwc600:1.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:pwc600:1.1:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:pwc600:1.2:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:reb500:7:*:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:reb500:8:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:relion670:1.2.*:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:relion670:2.0.*:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:relion650:1.1.*:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:relion650:1.3.*:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:relion650:2.1.*:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:relion670:2.1.*:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:relionSAM600-IO:2.2.1:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:relionSAM600-IO:2.2.5:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:relion670:2.2.*:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:relion650:2.2.*:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:rtu500cmu:12.*.*:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:rtu500cmu:13.*.*:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:txpert_hub_coretec_4:2.*:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:txpert_hub_coretec_4:3.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:txpert_hub_coretec_5:3.0:*:*:*:*:*:*:*

Credit: cybersecurity@hitachienergy.com

Affected SoftwareAffected VersionHow to fix
Hitachienergy Sys600 Firmware>=10.1<=10.3.1
Hitachienergy Sys600
Hitachienergy Rtu500 Firmware>=12.0.1.0<=12.0.14.0
Hitachienergy Rtu500 Firmware>=12.2.1.0<=12.2.11.0
Hitachienergy Rtu500 Firmware>=12.4.1.0<=12.4.11.0
Hitachienergy Rtu500 Firmware>=12.6.1.0<=12.6.8.0
Hitachienergy Rtu500 Firmware>=12.7.1.0<=12.7.4.0
Hitachienergy Rtu500 Firmware>=13.2.1.0<=13.2.5.0
Hitachienergy Rtu500 Firmware>=13.3.1<=13.3.3
Hitachienergy Rtu500 Firmware=13.4.1
Hitachienergy Rtu500
Hitachienergy Reb500 Firmware>=7.0<8.3.3
Hitachienergy Reb500
Hitachienergy Pwc600 Firmware=1.0
Hitachienergy Pwc600 Firmware=1.1
Hitachienergy Pwc600 Firmware=1.2
Hitachienergy Pwc600
Hitachienergy Modular Switchgear Monitoring Firmware<=2.2.3
Hitachienergy Modular Switchgear Monitoring
Hitachienergy Itt600 Sa Explorer=1.1.0
Hitachienergy Itt600 Sa Explorer=1.1.1
Hitachienergy Itt600 Sa Explorer=1.1.2
Hitachienergy Itt600 Sa Explorer=1.5.0
Hitachienergy Itt600 Sa Explorer=1.5.1
Hitachienergy Itt600 Sa Explorer=1.6.0
Hitachienergy Itt600 Sa Explorer=1.6.0.1
Hitachienergy Itt600 Sa Explorer=1.7.0
Hitachienergy Itt600 Sa Explorer=1.7.2
Hitachienergy Itt600 Sa Explorer=1.8.0
Hitachienergy Itt600 Sa Explorer=2.0.1
Hitachienergy Itt600 Sa Explorer=2.0.2
Hitachienergy Itt600 Sa Explorer=2.0.3
Hitachienergy Itt600 Sa Explorer=2.0.4.1
Hitachienergy Itt600 Sa Explorer=2.0.5.0
Hitachienergy Itt600 Sa Explorer=2.0.5.4
Hitachienergy Itt600 Sa Explorer=2.1.0.4
Hitachienergy Itt600 Sa Explorer=2.1.0.5
Hitachienergy Relion Sam600-io Firmware=2.2.1
Hitachienergy Relion Sam600-io Firmware=2.2.5
Hitachienergy Relion Sam600-io
Hitachienergy Relion 650 Firmware=1.1
Hitachienergy Relion 650 Firmware=1.3
Hitachienergy Relion 650 Firmware=2.1
Hitachienergy Relion 650 Firmware=2.2.0
Hitachienergy Relion 650 Firmware=2.2.1
Hitachienergy Relion 650 Firmware=2.2.2
Hitachienergy Relion 650 Firmware=2.2.3
Hitachienergy Relion 650 Firmware=2.2.4
Hitachienergy Relion 650 Firmware=2.2.5
Hitachienergy Relion 650
Hitachienergy Relion 670 Firmware=1.2
Hitachienergy Relion 670 Firmware=2.0
Hitachienergy Relion 670 Firmware=2.1
Hitachienergy Relion 670 Firmware=2.2.0
Hitachienergy Relion 670 Firmware=2.2.1
Hitachienergy Relion 670 Firmware=2.2.2
Hitachienergy Relion 670 Firmware=2.2.3
Hitachienergy Relion 670 Firmware=2.2.4
Hitachienergy Relion 670 Firmware=2.2.5
Hitachienergy Relion 670
Hitachienergy Gms600 Firmware=1.3.0
Hitachienergy Gms600
Hitachienergy Fox615 Tego1 Firmware=r1b02
Hitachienergy Fox615 Tego1 Firmware=r1c07
Hitachienergy Fox615 Tego1 Firmware=r1d02
Hitachienergy Fox615 Tego1 Firmware=r1e01
Hitachienergy Fox615 Tego1 Firmware=r2b16
Hitachienergy Fox615 Tego1 Firmware=r2b16_03
Hitachienergy Fox615 Tego1 Firmware=r15b08
Hitachienergy Fox615 Tego1
Hitachienergy Txpert Hub Coretec 4 Firmware>=2.0.0<=3.0.0
Hitachienergy Txpert Hub Coretec 4
Hitachienergy Txpert Hub Coretec 5 Firmware=3.0.0
Hitachienergy Txpert Hub Coretec 5

Remedy

Upgrade the system once remediated version is available.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203