CVE-2022-3353 - CVE House
Back to Database
Status published Medium CVE-2022-3353

IEC 61850 MMS-Server Vulnerability in multiple Hitachi Energy Products

Vulnerability Description

A vulnerability exists in the IEC 61850 communication stack that affects multiple Hitachi Energy products.  An attacker could exploit the vulnerability by using a specially crafted message sequence, to force the IEC 61850 MMS-server communication stack, to stop accepting new MMS-client connections.  Already existing/established client-server connections are not affected. List of affected CPEs: * cpe:2.3:o:hitachienergy:fox61x_tego1:r15b08:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:fox61x_tego1:r2a16_3:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:fox61x_tego1:r2a16:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:fox61x_tego1:r1e01:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:fox61x_tego1:r1d02:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:fox61x_tego1:r1c07:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:fox61x_tego1:r1b02:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:gms600:1.3.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:itt600_sa_explorer:1.1.*:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:itt600_sa_explorer:1.5.*:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:itt600_sa_explorer:1.6.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:itt600_sa_explorer:1.6.0.1:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:itt600_sa_explorer:1.7.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:itt600_sa_explorer:1.7.2:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:itt600_sa_explorer:1.8.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:itt600_sa_explorer:2.0.*:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:itt600_sa_explorer:2.1.0.4:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:itt600_sa_explorer:2.1.0.5:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:microscada_x_sys600:10:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:microscada_x_sys600:10.*:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2.1:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3.1:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:microscada_x_sys600:10.4:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:microscada_x_sys600:10.4.1:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:mms:2.2.3:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:pwc600:1.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:pwc600:1.1:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:pwc600:1.2:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:reb500:7:*:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:reb500:8:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:relion670:1.2.*:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:relion670:2.0.*:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:relion650:1.1.*:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:relion650:1.3.*:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:relion650:2.1.*:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:relion670:2.1.*:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:relionSAM600-IO:2.2.1:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:relionSAM600-IO:2.2.5:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:relion670:2.2.*:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:relion650:2.2.*:*:*:*:*:*:*:* * cpe:2.3:o:hitachienergy:rtu500cmu:12.*.*:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:rtu500cmu:13.*.*:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:txpert_hub_coretec_4:2.*:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:txpert_hub_coretec_4:3.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:txpert_hub_coretec_5:3.0:*:*:*:*:*:*:*

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-3353

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Hitachi Energy

View all reports →

Affected Software

FOX61x TEGO1, GMS600, ITT600 SA Explorer, MicroSCADA X SYS600, MSM, PWC600, REB500, Relion® 670, Relion® 650, SAM600-IO, RTU500, TXpert Hub CoreTec 4, TXpert Hub CoreTec 5
Vulnerable Versions:
tego1_r16a11, tego1_r15b08, tego1_r2a16_03, tego1_r2a16, tego1_r1e01, tego1_r1d02, tego1_r1c07, tego1_r1b02, GMS600 1.3, ITT600 SA Explorer 1.1.0, ITT600 SA Explorer 1.1.1, ITT600 SA Explorer 1.1.2, ITT600 SA Explorer 1.5.0, ITT600 SA Explorer 1.5.1, ITT600 SA Explorer 1.6.0, ITT600 SA Explorer 1.6.0.1, ITT600 SA Explorer 1.7.0, ITT600 SA Explorer 1.7.2, ITT600 SA Explorer 1.8.0, ITT600 SA Explorer 2.0.1, ITT600 SA Explorer 2.0.2, ITT600 SA Explorer 2.0.3, ITT600 SA Explorer 2.0.4.1, ITT600 SA Explorer 2.0.5.0, ITT600 SA Explorer 2.0.5.4, ITT600 SA Explorer 2.1.0.4, ITT600 SA Explorer 2.1.0.5, ITT600 SA Explorer 2.1.1.2, SYS600 10, SYS600 10.1, SYS600 10.1.1, SYS600 10.2, SYS600 10.2.1, SYS600 10.3, SYS600 10.3.1, SYS600 10.4, SYS600 10.4.1, MSM 2.2.3;0, PWC600 1.0, PWC600 1.1, PWC600 1.2, REB500 7.0, REB500 8.0, REB500 8.3.3.0, Relion 670 1.2, Relion 670 2.0, Relion 670 version 2.1, Relion 670 2.2.0, Relion 670 2.2.1, Relion 670 2.2.2, Relion 670 2.2.3, Relion 670 2.2.4, Relion 670 2.2.5, Relion 650 1.1, Relion 650 1.3, Relion 650 2.1, Relion 650 2.2.0, Relion 650 2.2.1, Relion 650 2.2.2, Relion 650 2.2.3, Relion 650 2.2.4, Relion 650 2.2.5, Relion SAM600-IO 2.2.1, Relion SAM600-IO 2.2.5, RTU500 12.0.1, RTU500 12.0.15, RTU500 12.2.1, RTU500 12.2.12, RTU500 12.4.1, RTU500 12.4.12, RTU500 12.6.1, RTU500 12.6.9, RTU500 12.7.1, RTU500 12.7.5, RTU500 13.2.1, RTU500 13.2.6, RTU500 13.3.1, RTU500 13.3.4, RTU500 13.4.1, RTU500 13.4.2, CoreTec 4 version 2.0.*, CoreTec 4 version 2.1.*, CoreTec 4 version 2.2.*, CoreTec 4 version 2.3.*, CoreTec 4 version 2.4.*, CoreTec 4 version 3.0.*, CoreTec 5 version 3.0.*

Timeline

Official Publish: February 21st, 2023
Last Modified: March 12th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)