Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-35533

Опубликовано: 26 нояб. 2021
Источник: nvd
CVSS3: 7.5
CVSS2: 7.1
EPSS Низкий

Описание

Improper Input Validation vulnerability in the APDU parser in the Bidirectional Communication Interface (BCI) IEC 60870-5-104 function of Hitachi Energy RTU500 series allows an attacker to cause the receiving RTU500 CMU of which the BCI is enabled to reboot when receiving a specially crafted message. By default, BCI IEC 60870-5-104 function is disabled (not configured). This issue affects: Hitachi Energy RTU500 series CMU Firmware version 12.0.* (all versions); CMU Firmware version 12.2.* (all versions); CMU Firmware version 12.4.* (all versions).

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:o:hitachienergy:rtu500_firmware:12.0:*:*:*:*:*:*:*
cpe:2.3:o:hitachienergy:rtu500_firmware:12.2:*:*:*:*:*:*:*
cpe:2.3:o:hitachienergy:rtu500_firmware:12.4:*:*:*:*:*:*:*
cpe:2.3:h:hitachienergy:rtu500:-:*:*:*:*:*:*:*

EPSS

Процентиль: 67%
0.00552
Низкий

7.5 High

CVSS3

7.1 High

CVSS2

Дефекты

CWE-20
CWE-20

Связанные уязвимости

CVSS3: 7.5
github
около 4 лет назад

Improper Input Validation vulnerability in the APDU parser in the Bidirectional Communication Interface (BCI) IEC 60870-5-104 function of Hitachi Energy RTU500 series allows an attacker to cause the receiving RTU500 CMU of which the BCI is enabled to reboot when receiving a specially crafted message. By default, BCI IEC 60870-5-104 function is disabled (not configured). This issue affects: Hitachi Energy RTU500 series CMU Firmware version 12.0.* (all versions); CMU Firmware version 12.2.* (all versions); CMU Firmware version 12.4.* (all versions).

EPSS

Процентиль: 67%
0.00552
Низкий

7.5 High

CVSS3

7.1 High

CVSS2

Дефекты

CWE-20
CWE-20