Skip to content
  Saturday 24 May 2025
Trending
April 8, 2024Sr. Cybersecurity Consultant – Hybrid February 12, 2025Cybersecurity Specialist December 31, 2024Cybersecurity Account Executive (Remote NY, NJ Metro) September 1, 2024Summer 2025 Risk Advisory Intern – Cybersecurity April 25, 2024Cybersecurity Senior Manager – Business Office December 18, 2023Data of 14.7 Million Affected in Mr. Cooper Hacking Incident February 12, 2024Cybersecurity Engineer III May 8, 2025Cybersecurity Analyst January 15, 20228 Best Free Movie Streaming Sites For 2022 – No Sign-Up Required May 21, 2025Senior Cybersecurity Engineer
Mister Cybersecurity
  • Home
  • News
    • Daily Update
    • Industry News
    • Threat Advisories
  • Simulators
    • Exam Simulators
      • CompTIA Security+
      • CompTIA Advanced Security Practitioner (CASP+)
      • Certified Ethical Hacker (CEH)
      • Certified Information Systems Security Professional (CISSP)
      •  Certified Information Systems Auditor (CISA)
      • Certified Information Security Manager (CISM)
      • Systems Security Certified Practitioner (SSCP)
      • GIAC Security Essentials Certification (GSEC)
      • GIAC Certified Incident Handler (GCIH)
      • Offensive Security Certified Professional (OSCP)
    • Training Simulators
      • Blue Team Simulator
      • Red Team Simulator
  • Tools
    • VulnVisor – Vulnerability Explorer
    • Takedown Request Generator
    • Dark Coder – Auto Code Generator
    • SKY VPN
  • Courses
    • SQL Injection Fundamentals with Kali Linux
    • Web Application Hacking
    • Session Hijacking
    • DoS & DDoS Attacks for Beginners
    • Cryptography for Cybersecurity & Hacking
    • Evasion Tactics – IDS, Firewalls & Honeypots
  • Tutorials
    • Security
    • Malware
    • Virus
    • Social Media Security
    • Wireless Security
    • Linux
    • Privacy
    • Windows
      • Windows 11
    • Android
    • iPhone
  • Software
    • Antivirus
    • Android APK
    • Best Free VPN
    • Encryption Tools
    • Hacking Tools
    • Network Utilities
    • Pentesting Tools
    • Themes and Skins
    • Operating Systems
  • More
    • Alternative Sites
    • Cloud Storage
    • Chrome OS
    • Encryption
    • Email Security
    • Ethical Hacking Books
    • Firewall
    • Hacking
    • Web
    • Ransomware
  • Careers
  • Store
  • Account
    • Log In
    • Your Profile
    • Membership Billing
    • Membership Account
Mister Cybersecurity
Mister Cybersecurity
  • Home
  • News
    • Daily Update
    • Industry News
    • Threat Advisories
  • Simulators
    • Exam Simulators
      • CompTIA Security+
      • CompTIA Advanced Security Practitioner (CASP+)
      • Certified Ethical Hacker (CEH)
      • Certified Information Systems Security Professional (CISSP)
      •  Certified Information Systems Auditor (CISA)
      • Certified Information Security Manager (CISM)
      • Systems Security Certified Practitioner (SSCP)
      • GIAC Security Essentials Certification (GSEC)
      • GIAC Certified Incident Handler (GCIH)
      • Offensive Security Certified Professional (OSCP)
    • Training Simulators
      • Blue Team Simulator
      • Red Team Simulator
  • Tools
    • VulnVisor – Vulnerability Explorer
    • Takedown Request Generator
    • Dark Coder – Auto Code Generator
    • SKY VPN
  • Courses
    • SQL Injection Fundamentals with Kali Linux
    • Web Application Hacking
    • Session Hijacking
    • DoS & DDoS Attacks for Beginners
    • Cryptography for Cybersecurity & Hacking
    • Evasion Tactics – IDS, Firewalls & Honeypots
  • Tutorials
    • Security
    • Malware
    • Virus
    • Social Media Security
    • Wireless Security
    • Linux
    • Privacy
    • Windows
      • Windows 11
    • Android
    • iPhone
  • Software
    • Antivirus
    • Android APK
    • Best Free VPN
    • Encryption Tools
    • Hacking Tools
    • Network Utilities
    • Pentesting Tools
    • Themes and Skins
    • Operating Systems
  • More
    • Alternative Sites
    • Cloud Storage
    • Chrome OS
    • Encryption
    • Email Security
    • Ethical Hacking Books
    • Firewall
    • Hacking
    • Web
    • Ransomware
  • Careers
  • Store
  • Account
    • Log In
    • Your Profile
    • Membership Billing
    • Membership Account
Mister Cybersecurity
  Threat Advisories  Hitachi Energy IEC 61850 MMS-Server
Threat Advisories

Hitachi Energy IEC 61850 MMS-Server

Mister CybersecurityMister Cybersecurity—March 30, 20230
FacebookTwitterPinterestLinkedInTumblrRedditVKWhatsAppEmail


1. EXECUTIVE SUMMARY

  • CVSS v3 5.9
  • ATTENTION: Exploitable remotely
  • Vendor: Hitachi Energy
  • Equipment: IEC 61850 MMS-Server
  • Vulnerability: Improper Resource Shutdown or Release

2. RISK EVALUATION

Successful exploitation of this vulnerability could cause products using the IEC 61850 MMS-server communication stack to stop accepting new MMS-client connections.

3. TECHNICAL DETAILS

3.1 AFFECTED PRODUCTS

The following versions Hitachi Energy equipment using the IEC 61850 communication stack are affected:

  • TXpert Hub CoreTec 4 version 2.0.x
  • TXpert Hub CoreTec 4 version 2.1.x
  • TXpert Hub CoreTec 4 version 2.2.x
  • TXpert Hub CoreTec 4 version 2.3.x
  • TXpert Hub CoreTec 4 version 2.4.x
  • TXpert Hub CoreTec 4 version 3.0.x
  • TXpert Hub CoreTec 5 version 3.0.x
  • Tego1_r15b08 (FOX615 System Release R15B)
  • Tego1_r2a16_03 (FOX615 System Release R14A)
  • Tego1_r2a16
  • Tego1_r1e01
  • Tego1_r1d02
  • Tego1_r1c07
  • Tego1_r1b02
  • GMS600 version 1.3
  • Relion 670 1.2 (Limited)
  • Relion 670 2.0 (Limited)
  • Relion 650 version 1.1 (Limited)
  • Relion 650 version 1.3 (Limited)
  • Relion 650 version 2.1 (Classic)
  • Relion 670 version 2.1 (Classic)
  • Relion SAM600-IO 2.2.1
  • Relion SAM600-IO 2.2.5
  • Relion 670/650 version 2.2.0
  • Relion 670/650 version 2.2.1
  • Relion 670/650 version 2.2.2
  • Relion 670/650 version 2.2.3
  • Relion 670/650 version 2.2.4
  • Relion 670/650 version 2.2.5
  • ITT600 SA Explorer version 1.1.0
  • ITT600 SA Explorer version 1.1.1
  • ITT600 SA Explorer version 1.1.2
  • ITT600 SA Explorer version 1.5.0
  • ITT600 SA Explorer version 1.5.1
  • ITT600 SA Explorer version 1.6.0
  • ITT600 SA Explorer version 1.6.0.1
  • ITT600 SA Explorer version 1.7.0
  • ITT600 SA Explorer version 1.7.2
  • ITT600 SA Explorer version 1.8.0
  • ITT600 SA Explorer version 2.0.1
  • ITT600 SA Explorer version 2.0.2
  • ITT600 SA Explorer version 2.0.3
  • ITT600 SA Explorer version 2.0.4.1
  • ITT600 SA Explorer version 2.0.5.0
  • ITT600 SA Explorer version 2.0.5.4
  • ITT600 SA Explorer version 2.1.0.4
  • ITT600 SA Explorer version 2.1.0.5
  • MSM version 2.2.3 and prior
  • PWC600 version 1.0
  • PWC600 version 1.1
  • PWC600 version 1.2
  • REB500 all V8.x versions
  • REB500 all V7.x versions
  • RTU500 series CMU Firmware version 12.0.1 to 12.0.14
  • RTU500 series CMU Firmware version 12.2.1 to 12.2.11
  • RTU500 series CMU Firmware version 12.4.1 to 12.4.11
  • RTU500 series CMU Firmware version 12.6.1 to 12.6.8  
  • RTU500 series CMU Firmware version 12.7.1 to 12.7.4  
  • RTU500 series CMU Firmware version 13.2.1 to 13.2.5  
  • RTU500 series CMU Firmware version 13.3.1 to 13.3.3  
  • RTU500 series CMU Firmware version 13.4.1
  • SYS600 version 10.1 to 10.3.1

3.2 VULNERABILITY OVERVIEW

3.2.1 IMPROPER RESOURCE SHUTDOWN OR RELEASE CWE-404
An attacker could exploit the IEC 61850 MMS-Server communication stack by forcing the communication stack to stop accepting new MMS-client connections.

CVE-2022-3353 has been assigned to this vulnerability. A CVSS v3.1 base score of 5.9 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).

3.3 BACKGROUND

  • CRITICAL INFRASTRUCTURE SECTORS: Energy
  • COUNTRIES/AREAS DEPLOYED: Worldwide
  • COMPANY HEADQUARTERS LOCATION: Switzerland

3.4 RESEARCHER

More stories

Emerson PACSystem and Fanuc | CISA

June 6, 2024

​APSystems Altenergy Power Control | CISA

August 1, 2023

IOSIX IO-1020 Micro ELD | CISA

April 2, 2024

CISA Adds One Known Exploited Vulnerability to Catalog

September 21, 2023

Hitachi Energy reported this vulnerability to CISA.

4. MITIGATIONS

Hitachi Energy provided updates for the following products. Contact Hitachi Energy for update information.

  • MSM Server update to version 2.2.5
  • tego1_r15b08 (FOX615 System Release R15B) update to tego1_r16a11 (FOX615 System Release R16A)
  • REB500 all V8.x versions update to REB500 firmware to version 8.3.3.0 when released.
  • RTU500 series CMU Firmware version 12.0.1 to 12.0.14 Update to CMU Firmware version 12.0.15
  • RTU500 series CMU Firmware version 12.2.1 to 12.2.11 Update to CMU Firmware version 12.2.12
  • RTU500 series CMU Firmware version 12.4.1 to 12.4.11 Update to CMU Firmware version 12.4.12
  • RTU500 series CMU Firmware version 12.6.1 to 12.6.8 Update to CMU Firmware version 12.6.9
  • RTU500 series CMU Firmware version 12.7.1 to 12.7.4 Update to CMU Firmware version 12.7.5
  • RTU500 series CMU Firmware version 13.2.1 to 13.2.5 Update to CMU Firmware version 13.2.6
  • RTU500 series CMU Firmware version 13.3.1 to 13.3.3 Update to CMU Firmware version 13.3.4
  • RTU500 series CMU Firmware version 13.4.1 Update to CMU Firmware version 13.4.2
  • SYS600 version 10.1 to 10.3.1 update to SYS600 version 10.4.1

For all versions, Hitachi Energy recommends that users apply these general mitigation factors: 

  • Upgrade the system once a remediated version is available.
  • Apply Hitachi Energy recommended security practices and firewall configurations to help protect a process control network from attacks that originate from outside the network. Such practices include: 
    • Physically protecting process control systems from direct access by unauthorized personnel.
    • Not allowing direct connections to the internet.
      • Process control systems should not be used for internet surfing, instant messaging, or receiving emails.
    • Use a firewall system that has a minimal number of exposed ports to separate the process control network from other networks. 
      • Connection to other networks must be evaluated as necessary. 
    • Scan portable computers and removable storage media carefully for viruses before connection to a control system.
  • MSM is not designed nor intended to be connected to the internet. Disconnect the device from any internet facing network.
    • Adopt user access management and updated antivirus protection engines equipped with the latest signature rules for computers that have installed and are operating the MMS Client application. 
    • Use the default operating system (OS) user access management function to limit unauthorized access and/or rogue commands via the MMS Client application.

For more information, see the Hitachi Energy advisories for the corresponding affected products: 

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage at cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

No known public exploits specifically target this vulnerability. This vulnerability has a high attack complexity.



Source link

FacebookTwitterPinterestLinkedInTumblrRedditVKWhatsAppEmail

Mister Cybersecurity

Supply Chain Attack Against 3CXDesktopApp
CISA Releases One Industrial Control Systems Advisory
Related posts
  • Related posts
  • More from author
Threat Advisories

Advisory Update on Cyber Threat Activity Targeting Commvault’s SaaS Cloud Application (Metallic)

May 22, 20250
Threat Advisories

Lantronix Device Installer | CISA

May 22, 20250
Threat Advisories

CISA Adds One Known Exploited Vulnerability to Catalog

May 22, 20250
Load more
Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Read also
Industry News

Rethinking Risk in the AI Era

May 24, 20250
Industry News

Hack on UK Legal Aid Agency Jeopardizes Legal Representation

May 23, 20250
Industry News

Global Darknet Bust: ‘Operation RapTor’ Strikes Criminal Networks

May 23, 20250
Industry News

Unmasking Threats: Exclusive Google Intelligence Webinar

May 23, 20250
Industry News

Cognyte Amplifies Threat Intelligence with $4M GroupSense Acquisition

May 23, 20250
Industry News

Hackers Spread Vidar and StealC Malware Through TikTok Videos Using ClickFix Technique

May 23, 20250
Load more
Stay Social!
192Likes
4,500Followers
13Subscribers
46Followers
Recent posts
  • Rethinking Risk in the AI Era

  • Hack on UK Legal Aid Agency Jeopardizes Legal Representation

  • Global Darknet Bust: ‘Operation RapTor’ Strikes Criminal Networks

  • Unmasking Threats: Exclusive Google Intelligence Webinar

  • Cognyte Amplifies Threat Intelligence with $4M GroupSense Acquisition

    # TRENDING

    how old is my computerhow old is my dell laptophow old is my HP laptophow old is my laptophow old is my toshiba laptophow to find computer ageverify computer agestar wars theme wallpapersThe Best Hacking Bookswiresharkusb device not found windows 10/11usb device not recognized windows 10/11 errorWhat is AIGPUSnifferuTorrentvulnerability scanner downloadWifi Hacking SoftwareWifi Hacking Appsolved windows 10/11 usb device not recognizedstar wars windows 7 theme downloadTwitter Account Security
    © Copyright Mister Cybersecurity LLC 2023, All Rights Reserved
    • About
    • Contact
    • Privacy
    • ToS
    • Disclosures