IEC 60870-5-104: Potential Denial of Service impact on reception of invalid U-format frame. Product is only affected if IEC 60870-5-104 bi-directional functionality is configured. Enabling secure communication following IEC 62351-3 does not remediate the vulnerability but mitigates the risk of exploitation.
The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Rtu540_firmware | Hitachienergy | 12.7.1 (including) | 12.7.7 (including) |
| Rtu540_firmware | Hitachienergy | 13.5.1 (including) | 13.5.4 (including) |
| Rtu540_firmware | Hitachienergy | 13.6.1 (including) | 13.6.2 (including) |
| Rtu540_firmware | Hitachienergy | 13.7.1 (including) | 13.7.8 (excluding) |
| Rtu540_firmware | Hitachienergy | 13.8.1 (including) | 13.8.1 (including) |