7.5
CVE-2022-2081
- EPSS 0.16%
- Veröffentlicht 04.01.2024 10:15:10
- Zuletzt bearbeitet 21.11.2024 07:00:17
- Quelle cybersecurity@hitachienergy.co
- Teams Watchlist Login
- Unerledigt Login
A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is enabled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500 in a high rate, causing the targeted RTU500 CMU to reboot. The vulnerability is caused by a lack of flood control which eventually if exploited causes an internal stack overflow in the HCI Modbus TCP function.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hitachienergy ≫ Rtu520 Firmware Version >= 12.0.1 <= 12.0.13
Hitachienergy ≫ Rtu520 Firmware Version >= 12.2.1 <= 12.2.11
Hitachienergy ≫ Rtu520 Firmware Version >= 12.4.1 <= 12.4.11
Hitachienergy ≫ Rtu520 Firmware Version >= 12.6.1 <= 12.6.7
Hitachienergy ≫ Rtu520 Firmware Version >= 12.7.1 <= 12.7.3
Hitachienergy ≫ Rtu520 Firmware Version >= 13.2.1 <= 13.2.4
Hitachienergy ≫ Rtu520 Firmware Version13.3.1
Hitachienergy ≫ Rtu530 Firmware Version >= 12.0.1 <= 12.0.13
Hitachienergy ≫ Rtu530 Firmware Version >= 12.2.1 <= 12.2.11
Hitachienergy ≫ Rtu530 Firmware Version >= 12.4.1 <= 12.4.11
Hitachienergy ≫ Rtu530 Firmware Version >= 12.6.1 <= 12.6.7
Hitachienergy ≫ Rtu530 Firmware Version >= 12.7.1 <= 12.7.3
Hitachienergy ≫ Rtu530 Firmware Version >= 13.2.1 <= 13.2.4
Hitachienergy ≫ Rtu530 Firmware Version13.3.1
Hitachienergy ≫ Rtu540 Firmware Version >= 12.0.1 <= 12.0.13
Hitachienergy ≫ Rtu540 Firmware Version >= 12.2.1 <= 12.2.11
Hitachienergy ≫ Rtu540 Firmware Version >= 12.4.1 <= 12.4.11
Hitachienergy ≫ Rtu540 Firmware Version >= 12.6.1 <= 12.6.7
Hitachienergy ≫ Rtu540 Firmware Version >= 12.7.1 <= 12.7.3
Hitachienergy ≫ Rtu540 Firmware Version >= 13.2.1 <= 13.2.4
Hitachienergy ≫ Rtu540 Firmware Version13.3.1
Hitachienergy ≫ Rtu560 Firmware Version >= 12.0.1 <= 12.0.13
Hitachienergy ≫ Rtu560 Firmware Version >= 12.2.1 <= 12.2.11
Hitachienergy ≫ Rtu560 Firmware Version >= 12.4.1 <= 12.4.11
Hitachienergy ≫ Rtu560 Firmware Version >= 12.6.1 <= 12.6.7
Hitachienergy ≫ Rtu560 Firmware Version >= 12.7.1 <= 12.7.3
Hitachienergy ≫ Rtu560 Firmware Version >= 13.2.1 <= 13.2.4
Hitachienergy ≫ Rtu560 Firmware Version13.3.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.16% | 0.368 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
cybersecurity@hitachienergy.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.