CVE-2021-35533
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
26/11/2021
Last modified:
16/05/2023
Description
Improper Input Validation vulnerability in the APDU parser in the Bidirectional Communication Interface (BCI) IEC 60870-5-104 function of Hitachi Energy RTU500 series allows an attacker to cause the receiving RTU500 CMU of which the BCI is enabled to reboot when receiving a specially crafted message. By default, BCI IEC 60870-5-104 function is disabled (not configured). This issue affects: Hitachi Energy RTU500 series CMU Firmware version 12.0.* (all versions); CMU Firmware version 12.2.* (all versions); CMU Firmware version 12.4.* (all versions).
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
7.10
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:hitachienergy:rtu500_firmware:12.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hitachienergy:rtu500_firmware:12.2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hitachienergy:rtu500_firmware:12.4:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hitachienergy:rtu500:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



