CVE-2023-6711
Estado: ModificadaAlta (7.5)—
Vulnerability exists in SCI IEC 60870-5-104 and HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Specially crafted messages sent to the mentioned components are not validated properly and can result in buffer overflow and as final consequence to a reboot of an RTU500 CMU.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.67%
- Percentil entre todas las CVEs puntuadas: 50
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-120
- CWE-120
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-6711",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cybersecurity@hitachienergy.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.2
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cybersecurity@hitachienergy.com",
"affectedData": [
{
"vendor": "Hitachi Energy",
"product": "RTU500 series CMU Firmware",
"versions": [
{
"status": "affected",
"version": "12.0.1",
"versionType": "custom",
"lessThanOrEqual": "12.0.14"
},
{
"status": "affected",
"version": "12.2.1",
"versionType": "custom",
"lessThanOrEqual": "12.2.11"
},
{
"status": "affected",
"version": "12.4.1",
"versionType": "custom",
"lessThanOrEqual": "12.4.11"
},
{
"status": "affected",
"version": "12.6.1",
"versionType": "custom",
"lessThanOrEqual": "12.6.9"
},
{
"status": "affected",
"version": "12.7.1",
"versionType": "custom",
"lessThanOrEqual": "12.7.6"
},
{
"status": "affected",
"version": "13.2.1",
"versionType": "custom",
"lessThanOrEqual": "13.2.6"
},
{
"status": "affected",
"version": "13.4.1",
"versionType": "custom",
"lessThanOrEqual": "13.4.3"
},
{
"status": "affected",
"version": "13.5.1"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-12-19T15:15:09.257",
"references": [
{
"url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000184&languageCode=en&Preview=true",
"tags": [
"Vendor Advisory"
],
"source": "cybersecurity@hitachienergy.com"
},
{
"url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000184&languageCode=en&Preview=true",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cybersecurity@hitachienergy.com",
"description": [
{
"lang": "en",
"value": "CWE-120"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-120"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Vulnerability exists in SCI IEC 60870-5-104 and HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Specially crafted messages sent to the mentioned components are not validated properly and can result in buffer overflow and as final consequence to a reboot of an RTU500 CMU."
},
{
"lang": "es",
"value": "Existe una vulnerabilidad en SCI IEC 60870-5-104 y HCI IEC 60870-5-104 que afecta a las versiones de productos de RTU500 series que se enumeran a continuación. Los mensajes especialmente manipulados enviados a los componentes mencionados no se validan correctamente y pueden provocar un desbordamiento de búfer y, como consecuencia final, un reinicio de una CMU RTU500."
}
],
"lastModified": "2026-06-17T06:51:17.293",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E50C1390-D171-43AA-91BB-BCE40AB8B4F5",
"versionEndExcluding": "12.0.15.0",
"versionStartIncluding": "12.0.1.0"
},
{
"criteria": "cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "99416778-6B10-4C85-BC6A-AA9D77707489",
"versionEndExcluding": "12.2.12.0",
"versionStartIncluding": "12.2.1.0"
},
{
"criteria": "cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "229DCAE7-8362-4C5F-B708-9B130123DAAC",
"versionEndExcluding": "12.4.12.0",
"versionStartIncluding": "12.4.1.0"
},
{
"criteria": "cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6241D442-A026-4F8D-88CA-AF8A3AEB3F57",
"versionEndExcluding": "12.6.10.0",
"versionStartIncluding": "12.6.1.0"
},
{
"criteria": "cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "71BCAE0B-3CD2-495E-B44B-661656C4BD05",
"versionEndExcluding": "12.7.7.0",
"versionStartIncluding": "12.7.1.0"
},
{
"criteria": "cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "01D33538-A8C2-4FC3-84B3-5F43E7ABA6E8",
"versionEndExcluding": "13.2.7.0",
"versionStartIncluding": "13.2.1.0"
},
{
"criteria": "cpe:2.3:o:hitachienergy:rtu500_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6E7961A7-DA10-498D-B746-A35782A2C4DC",
"versionEndExcluding": "13.4.4.0",
"versionStartIncluding": "13.4.1.0"
},
{
"criteria": "cpe:2.3:o:hitachienergy:rtu500_firmware:13.5.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A3F2C69B-BDFA-42A2-B0DF-50D690CC5024"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hitachienergy:rtu500:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DE94252D-03EE-451B-8322-B4DBC790C6E9"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cybersecurity@hitachienergy.com"
}