CVE-2022-2277

Improper Input Validation vulnerability exists in the Hitachi Energy MicroSCADA X SYS600's ICCP stack during the ICCP communication establishment causes a denial-of-service when ICCP of SYS600 is request to forward any data item updates with timestamps too distant in the future to any remote ICCP system. By default, ICCP is not configured and not enabled. This issue affects: Hitachi Energy MicroSCADA X SYS600 version 10.2 to version 10.3.1. cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3.1:*:*:*:*:*:*:*
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:hitachienergy:microscada_x_sys600:*:*:*:*:*:*:*:*
cpe:2.3:h:hitachienergy:sys600:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:00

Type Values Removed Values Added
References
  • () https://search.abb.com/library/Download.aspx?DocumentID=8DBD000106&LanguageCode=en&DocumentPartId=&Action=Launch -

25 Sep 2024, 11:15

Type Values Removed Values Added
References
  • {'url': 'https://publisher.hitachienergy.com/preview?DocumentId=8DBD000106&languageCode=en&Preview=true', 'source': 'cybersecurity@hitachienergy.com'}
  • () https://publisher.hitachienergy.com/preview?DocumentID=8DBD000106&LanguageCode=en&DocumentPartId=&Action=Launch -

23 Sep 2024, 13:15

Type Values Removed Values Added
CWE CWE-20
References
  • {'url': 'https://search.abb.com/library/Download.aspx?DocumentID=8DBD000106&LanguageCode=en&DocumentPartId=&Action=Launch', 'tags': ['Vendor Advisory'], 'source': 'cybersecurity@hitachienergy.com'}
  • () https://publisher.hitachienergy.com/preview?DocumentId=8DBD000106&languageCode=en&Preview=true -

21 Jul 2023, 19:26

Type Values Removed Values Added
CWE CWE-20 CWE-1284
CPE cpe:2.3:a:hitachi:microscada_x_sys600:*:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:sys600:-:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_x_sys600:*:*:*:*:*:*:*:*
cpe:2.3:h:hitachienergy:sys600:-:*:*:*:*:*:*:*

17 Sep 2022, 02:38

Type Values Removed Values Added
References (CONFIRM) https://search.abb.com/library/Download.aspx?DocumentID=8DBD000106&LanguageCode=en&DocumentPartId=&Action=Launch - (CONFIRM) https://search.abb.com/library/Download.aspx?DocumentID=8DBD000106&LanguageCode=en&DocumentPartId=&Action=Launch - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:hitachi:microscada_x_sys600:*:*:*:*:*:*:*:*
cpe:2.3:h:hitachi:sys600:-:*:*:*:*:*:*:*
CWE CWE-20

14 Sep 2022, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-09-14 18:15

Updated : 2024-11-21 07:00


NVD link : CVE-2022-2277

Mitre link : CVE-2022-2277

CVE.ORG link : CVE-2022-2277


JSON object : View

Products Affected

hitachienergy

  • sys600
  • microscada_x_sys600
CWE
CWE-1284

Improper Validation of Specified Quantity in Input