First published: Tue Dec 19 2023(Updated: )
Vulnerability exists in SCI IEC 60870-5-104 and HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Specially crafted messages sent to the mentioned components are not validated properly and can result in buffer overflow and as final consequence to a reboot of an RTU500 CMU.
Credit: cybersecurity@hitachienergy.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Hitachienergy Rtu500 Firmware | >=12.0.1.0<12.0.15.0 | |
Hitachienergy Rtu500 Firmware | >=12.2.1.0<12.2.12.0 | |
Hitachienergy Rtu500 Firmware | >=12.4.1.0<12.4.12.0 | |
Hitachienergy Rtu500 Firmware | >=12.6.1.0<12.6.10.0 | |
Hitachienergy Rtu500 Firmware | >=12.7.1.0<12.7.7.0 | |
Hitachienergy Rtu500 Firmware | >=13.2.1.0<13.2.7.0 | |
Hitachienergy Rtu500 Firmware | >=13.4.1.0<13.4.4.0 | |
Hitachienergy Rtu500 Firmware | =13.5.1.0 | |
Hitachienergy Rtu500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6711 has been classified with a high severity due to potential exploitation leading to a buffer overflow and device reboot.
To mitigate CVE-2023-6711, update the Hitachienergy RTU500 firmware to the latest version released by the vendor.
CVE-2023-6711 affects various versions of the Hitachienergy RTU500 firmware, specifically between 12.0.1.0 to 12.0.15.0, 12.2.1.0 to 12.2.12.0, 12.4.1.0 to 12.4.12.0, 12.6.1.0 to 12.6.10.0, 12.7.1.0 to 12.7.7.0, 13.2.1.0 to 13.2.7.0, and 13.4.1.0 to 13.4.4.0.
If CVE-2023-6711 is not addressed, specially crafted messages may cause a buffer overflow that could result in the reboot of an RTU500 device.
Organizations using the affected versions of Hitachienergy RTU500 firmware are at risk due to this vulnerability.