Show filters
324 Total Results
Displaying 61-70 of 324
Sort by:
Attacker Value
Unknown

CVE-2023-49107

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
Generation of Error Message Containing Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent modules).This issue affects Hitachi Device Manager: before 8.8.5-04.
Attacker Value
Unknown

CVE-2023-49106

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
Missing Password Field Masking vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent component).This issue affects Hitachi Device Manager: before 8.8.5-04.
Attacker Value
Unknown

CVE-2022-3864

Disclosure Date: January 04, 2024 (last updated January 11, 2024)
A vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED to restart. After restart the device is back to normal operation. An attacker could exploit the vulnerability by first gaining access to the system with security privileges and attempt to update the IED with a malicious update package. Successful exploitation of this vulnerability will cause the IED to restart, causing a temporary Denial of Service.
Attacker Value
Unknown

CVE-2022-2081

Disclosure Date: January 04, 2024 (last updated January 11, 2024)
A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is enabled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500 in a high rate, causing the targeted RTU500 CMU to reboot. The vulnerability is caused by a lack of flood control which eventually if exploited causes an internal stack overflow in the HCI Modbus TCP function.
Attacker Value
Unknown

CVE-2023-6711

Disclosure Date: December 19, 2023 (last updated December 29, 2023)
Vulnerability exists in SCI IEC 60870-5-104 and HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Specially crafted messages sent to the mentioned components are not validated properly and can result in buffer overflow and as final consequence to a reboot of an RTU500 CMU.
Attacker Value
Unknown

CVE-2023-1514

Disclosure Date: December 19, 2023 (last updated December 29, 2023)
A vulnerability exists in the component RTU500 Scripting interface. When a client connects to a server using TLS, the server presents a certificate. This certificate links a public key to the identity of the service and is signed by a Certification Authority (CA), allowing the client to validate that the remote service can be trusted and is not malicious. If the client does not validate the parameters of the certificate, then attackers could be able to spoof the identity of the service. An attacker could exploit the vulnerability by using faking the identity of a RTU500 device and intercepting the messages initiated via the RTU500 Scripting interface.
Attacker Value
Unknown

CVE-2023-5769

Disclosure Date: December 14, 2023 (last updated December 19, 2023)
A vulnerability exists in the webserver that affects the RTU500 series product versions listed below. A malicious actor could perform cross-site scripting on the webserver due to user input being improperly sanitized.
Attacker Value
Unknown

CVE-2023-3517

Disclosure Date: December 12, 2023 (last updated December 19, 2023)
Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.
Attacker Value
Unknown

CVE-2023-6538

Disclosure Date: December 11, 2023 (last updated December 15, 2023)
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Server or combined Server+Storage administrative roles are able to access SMU configuration backup, that would normally be barred to those specific administrative roles.
Attacker Value
Unknown

CVE-2023-5808

Disclosure Date: December 05, 2023 (last updated December 09, 2023)
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be barred to that specific administrative role.