PT-2022-5037 · Hitachi Energy · Hitachi Energy Microscada X Sys600
Published
2022-04-29
·
Updated
2022-10-05
·
CVE-2022-29922
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Hitachi Energy MicroSCADA Pro SYS600 versions 9.4 FP2 Hotfix 4 and earlier
Hitachi Energy MicroSCADA X SYS600 versions 10 through 10.3.1
Description
The issue is related to an Improper Input Validation vulnerability in the handling of a specially crafted IEC 61850 packet with a valid data item but with incorrect data type in the IEC 61850 OPC Server. This vulnerability may cause a denial-of-service on the IEC 61850 OPC Server part of the SYS600 product.
Recommendations
For Hitachi Energy MicroSCADA Pro SYS600 versions 9.4 FP2 Hotfix 4 and earlier, update to a version later than 9.4 FP2 Hotfix 4.
For Hitachi Energy MicroSCADA X SYS600 versions 10 through 10.3.1, update to a version later than 10.3.1.
As a temporary workaround, consider restricting access to the IEC 61850 OPC Server to minimize the risk of exploitation.
Fix
Improper Resource Release
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hitachi Energy Microscada X Sys600