PT-2022-5037 · Hitachi Energy · Hitachi Energy Microscada X Sys600

Published

2022-04-29

·

Updated

2022-10-05

·

CVE-2022-29922

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Hitachi Energy MicroSCADA Pro SYS600 versions 9.4 FP2 Hotfix 4 and earlier Hitachi Energy MicroSCADA X SYS600 versions 10 through 10.3.1
Description The issue is related to an Improper Input Validation vulnerability in the handling of a specially crafted IEC 61850 packet with a valid data item but with incorrect data type in the IEC 61850 OPC Server. This vulnerability may cause a denial-of-service on the IEC 61850 OPC Server part of the SYS600 product.
Recommendations For Hitachi Energy MicroSCADA Pro SYS600 versions 9.4 FP2 Hotfix 4 and earlier, update to a version later than 9.4 FP2 Hotfix 4. For Hitachi Energy MicroSCADA X SYS600 versions 10 through 10.3.1, update to a version later than 10.3.1. As a temporary workaround, consider restricting access to the IEC 61850 OPC Server to minimize the risk of exploitation.

Fix

Improper Resource Release

RCE

Weakness Enumeration

Related Identifiers

BDU:2022-06257
CVE-2022-29922

Affected Products

Hitachi Energy Microscada X Sys600