CVE-2023-6711: Buffer Overflow
Vulnerability exists in SCI IEC 60870-5-104 and HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Specially crafted messages sent to the mentioned components are not validated properly and can result in buffer overflow and as final consequence to a reboot of an RTU500 CMU.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6711?
CVE-2023-6711 has been classified with a high severity due to potential exploitation leading to a buffer overflow and device reboot.
How do I fix CVE-2023-6711?
To mitigate CVE-2023-6711, update the Hitachienergy RTU500 firmware to the latest version released by the vendor.
Which versions of the Hitachienergy RTU500 firmware are affected by CVE-2023-6711?
CVE-2023-6711 affects various versions of the Hitachienergy RTU500 firmware, specifically between 12.0.1.0 to 12.0.15.0, 12.2.1.0 to 12.2.12.0, 12.4.1.0 to 12.4.12.0, 12.6.1.0 to 12.6.10.0, 12.7.1.0 to 12.7.7.0, 13.2.1.0 to 13.2.7.0, and 13.4.1.0 to 13.4.4.0.
What could happen if I do not address CVE-2023-6711?
If CVE-2023-6711 is not addressed, specially crafted messages may cause a buffer overflow that could result in the reboot of an RTU500 device.
Who is affected by CVE-2023-6711?
Organizations using the affected versions of Hitachienergy RTU500 firmware are at risk due to this vulnerability.