Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5568-g9wp-2cv7

Опубликовано: 26 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-3. After session resumption interval is expired an RTU500 initiated update of session parameters causes an unexpected restart due to a stack overflow.

A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-3. After session resumption interval is expired an RTU500 initiated update of session parameters causes an unexpected restart due to a stack overflow.

EPSS

Процентиль: 17%
0.00052
Низкий

7.5 High

CVSS3

Дефекты

CWE-120
CWE-787

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-3. After session resumption interval is expired an RTU500 initiated update of session parameters causes an unexpected restart due to a stack overflow.

CVSS3: 7.5
fstec
больше 2 лет назад

Уязвимость интерфейса HCI (Host Controller Interface), функционирующего по стандарту IEC 60870-5-104, программируемых логических контроллеров Hitachi Energy RTU500, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 17%
0.00052
Низкий

7.5 High

CVSS3

Дефекты

CWE-120
CWE-787