U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2023-5768

Change History

New CVE Received by NIST 12/04/2023 10:15:07 AM

Action Type Old Value New Value
Added CVSS V3.1

								
							
							
						
Hitachi ABB Power Grids AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Added Description

								
							
							
						
A vulnerability exists in the HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. 
Incomplete or wrong received APDU frame layout may 
cause blocking on link layer. Error reason was an endless blocking when reading incoming frames on link layer 
with wrong length information of APDU or delayed reception 
of data octets.


Only communication link of affected HCI IEC 60870-5-104 
is blocked. If attack sequence stops the communication to 
the previously attacked link gets normal again.

Added Reference

								
							
							
						
Hitachi ABB Power Grids https://publisher.hitachienergy.com/preview?DocumentId=8DBD000176&languageCode=en&Preview=true [No types assigned]