CVE-2023-2622: Medium severity hitachienergy modular advanced control for hvdc vulnerability
Authenticated clients can read arbitrary files on the MAIN Computer system using the remote procedure call (RPC) of the InspectSetup service endpoint. The low privilege client is then allowed to read arbitrary files that they do not have authorization to read.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-2622?
CVE-2023-2622 is a vulnerability that allows authenticated clients to read arbitrary files on the MAIN Computer system using the remote procedure call (RPC) of the InspectSetup service endpoint.
What is the severity of CVE-2023-2622?
The severity of CVE-2023-2622 is medium with a severity value of 4.3.
Which software is affected by CVE-2023-2622?
The Hitachienergy Modular Advanced Control For Hvdc software versions 7.10.0.0 to 7.18.0.0 are affected by CVE-2023-2622.
How can authenticated clients exploit CVE-2023-2622?
Authenticated clients can exploit CVE-2023-2622 by using the remote procedure call (RPC) of the InspectSetup service endpoint to read arbitrary files on the MAIN Computer system.
Is there a fix for CVE-2023-2622?
Currently, there is no information available regarding a fix for CVE-2023-2622. It is recommended to follow the guidance provided by the vendor and keep the software up to date.