Security Advisory

CVE-2022-4608

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-07-26 05:26:42
Last updated 2025-03-05 18:46:44
Assigner Hitachi Energy
State PUBLISHED

Description

A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-3. After session resumption interval is expired an RTU500 initiated update of session parameters causes an unexpected restart due to a stack overflow.