CVE-2023-5767

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
04/12/2023
Last modified:
07/12/2023

Description

<br /> A vulnerability exists in the webserver that affects the <br /> RTU500 series product versions listed below. A malicious <br /> actor could perform cross-site scripting on the webserver <br /> due to an RDT language file being improperly sanitized.<br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hitachienergy:rtu520_firmware:*:*:*:*:*:*:*:* 12.0.1 (including) 12.0.14 (including)
cpe:2.3:o:hitachienergy:rtu520_firmware:*:*:*:*:*:*:*:* 12.2.1 (including) 12.2.11 (including)
cpe:2.3:o:hitachienergy:rtu520_firmware:*:*:*:*:*:*:*:* 12.4.1 (including) 12.4.11 (including)
cpe:2.3:o:hitachienergy:rtu520_firmware:*:*:*:*:*:*:*:* 12.6.1 (including) 12.6.9 (including)
cpe:2.3:o:hitachienergy:rtu520_firmware:*:*:*:*:*:*:*:* 12.7.1 (including) 12.7.6 (including)
cpe:2.3:o:hitachienergy:rtu520_firmware:*:*:*:*:*:*:*:* 13.2.1 (including) 13.2.6 (including)
cpe:2.3:o:hitachienergy:rtu520_firmware:*:*:*:*:*:*:*:* 13.4.1 (including) 13.4.3 (including)
cpe:2.3:h:hitachienergy:rtu520:-:*:*:*:*:*:*:*
cpe:2.3:o:hitachienergy:rtu530_firmware:*:*:*:*:*:*:*:* 12.0.1 (including) 12.0.14 (including)
cpe:2.3:o:hitachienergy:rtu530_firmware:*:*:*:*:*:*:*:* 12.2.1 (including) 12.2.11 (including)
cpe:2.3:o:hitachienergy:rtu530_firmware:*:*:*:*:*:*:*:* 12.4.1 (including) 12.4.11 (including)
cpe:2.3:o:hitachienergy:rtu530_firmware:*:*:*:*:*:*:*:* 12.6.1 (including) 12.6.9 (including)
cpe:2.3:o:hitachienergy:rtu530_firmware:*:*:*:*:*:*:*:* 12.7.1 (including) 12.7.6 (including)
cpe:2.3:o:hitachienergy:rtu530_firmware:*:*:*:*:*:*:*:* 13.2.1 (including) 13.2.6 (including)
cpe:2.3:o:hitachienergy:rtu530_firmware:*:*:*:*:*:*:*:* 13.4.1 (including) 13.4.3 (including)