6.1

CVE-2023-5768

A vulnerability exists in the HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. 
Incomplete or wrong received APDU frame layout may 
cause blocking on link layer. Error reason was an endless blocking when reading incoming frames on link layer 
with wrong length information of APDU or delayed reception 
of data octets.


Only communication link of affected HCI IEC 60870-5-104 
is blocked. If attack sequence stops the communication to 
the previously attacked link gets normal again.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HitachienergyRtu520 Firmware Version >= 12.0.1 <= 12.0.14
   HitachienergyRtu520 Version-
HitachienergyRtu520 Firmware Version >= 12.2.1 <= 12.2.11
   HitachienergyRtu520 Version-
HitachienergyRtu520 Firmware Version >= 12.4.1 <= 12.4.11
   HitachienergyRtu520 Version-
HitachienergyRtu520 Firmware Version >= 12.6.1 <= 12.6.9
   HitachienergyRtu520 Version-
HitachienergyRtu520 Firmware Version >= 12.7.1 <= 12.7.6
   HitachienergyRtu520 Version-
HitachienergyRtu520 Firmware Version >= 13.2.1 <= 13.2.6
   HitachienergyRtu520 Version-
HitachienergyRtu520 Firmware Version >= 13.4.1 <= 13.4.3
   HitachienergyRtu520 Version-
HitachienergyRtu530 Firmware Version >= 12.0.1 <= 12.0.14
   HitachienergyRtu530 Version-
HitachienergyRtu530 Firmware Version >= 12.2.1 <= 12.2.11
   HitachienergyRtu530 Version-
HitachienergyRtu530 Firmware Version >= 12.4.1 <= 12.4.11
   HitachienergyRtu530 Version-
HitachienergyRtu530 Firmware Version >= 12.6.1 <= 12.6.9
   HitachienergyRtu530 Version-
HitachienergyRtu530 Firmware Version >= 12.7.1 <= 12.7.6
   HitachienergyRtu530 Version-
HitachienergyRtu530 Firmware Version >= 13.2.1 <= 13.2.6
   HitachienergyRtu530 Version-
HitachienergyRtu530 Firmware Version >= 13.4.1 <= 13.4.3
   HitachienergyRtu530 Version-
HitachienergyRtu540 Firmware Version >= 12.0.1 <= 12.0.14
   HitachienergyRtu540 Version-
HitachienergyRtu540 Firmware Version >= 12.2.1 <= 12.2.11
   HitachienergyRtu540 Version-
HitachienergyRtu540 Firmware Version >= 12.4.1 <= 12.4.11
   HitachienergyRtu540 Version-
HitachienergyRtu540 Firmware Version >= 12.6.1 <= 12.6.9
   HitachienergyRtu540 Version-
HitachienergyRtu540 Firmware Version >= 12.7.1 <= 12.7.6
   HitachienergyRtu540 Version-
HitachienergyRtu540 Firmware Version >= 13.2.1 <= 13.2.6
   HitachienergyRtu540 Version-
HitachienergyRtu540 Firmware Version >= 13.4.1 <= 13.4.3
   HitachienergyRtu540 Version-
HitachienergyRtu560 Firmware Version >= 12.0.1 <= 12.0.14
   HitachienergyRtu560 Version-
HitachienergyRtu560 Firmware Version >= 12.2.1 <= 12.2.11
   HitachienergyRtu560 Version-
HitachienergyRtu560 Firmware Version >= 12.4.1 <= 12.4.11
   HitachienergyRtu560 Version-
HitachienergyRtu560 Firmware Version >= 12.6.1 <= 12.6.9
   HitachienergyRtu560 Version-
HitachienergyRtu560 Firmware Version >= 12.7.1 <= 12.7.6
   HitachienergyRtu560 Version-
HitachienergyRtu560 Firmware Version >= 13.2.1 <= 13.2.6
   HitachienergyRtu560 Version-
HitachienergyRtu560 Firmware Version >= 13.4.1 <= 13.4.3
   HitachienergyRtu560 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.07% 0.219
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cybersecurity@hitachienergy.com 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.