PT-2022-5037 · Hitachi Energy · Hitachi Energy Microscada X Sys600

CVE-2022-29922

·

Published

2022-04-29

·

Updated

2022-10-05

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Hitachi Energy MicroSCADA Pro SYS600 versions 9.4 FP2 Hotfix 4 and earlier Hitachi Energy MicroSCADA X SYS600 versions 10 through 10.3.1
Description The issue is related to an Improper Input Validation vulnerability in the handling of a specially crafted IEC 61850 packet with a valid data item but with incorrect data type in the IEC 61850 OPC Server. This vulnerability may cause a denial-of-service on the IEC 61850 OPC Server part of the SYS600 product.
Recommendations For Hitachi Energy MicroSCADA Pro SYS600 versions 9.4 FP2 Hotfix 4 and earlier, update to a version later than 9.4 FP2 Hotfix 4. For Hitachi Energy MicroSCADA X SYS600 versions 10 through 10.3.1, update to a version later than 10.3.1. As a temporary workaround, consider restricting access to the IEC 61850 OPC Server to minimize the risk of exploitation.

Fix

Improper Resource Release

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06257
CVE-2022-29922

Affected Products

Hitachi Energy Microscada X Sys600