Hitachi Energy AFS/AFR Series Products

View CSAF

1. EXECUTIVE SUMMARY

  • CVSS v3 7.5
  • ATTENTION: Exploitable remotely/low attack complexity
  • Vendor: Hitachi Energy
  • Equipment: AFS650, AFS660, AFS665, AFS670, AFS675, AFS677, AFR677
  • Vulnerabilities: Type Confusion, Use After Free, Double Free, Observable Discrepancy

2. RISK EVALUATION

Successful exploitation of these vulnerabilities could allow an attacker to create a denial-of-service condition.

3. TECHNICAL DETAILS

3.1 AFFECTED PRODUCTS

The following versions of Hitachi Energy AFS/AFR are affected:

  • AFS650: Version 9.1.08 and prior
  • AFS660-C: Version 7.1.05 and prior
  • AFS665-B: Version 7.1.05 and prior
  • AFS670-V2: Version 7.1.05 and prior
  • AFS670: Version 9.1.08 and prior
  • AFS675: Version 9.1.08 and prior
  • AFS677: Version 9.1.08 and prior
  • AFR677: Version 9.1.08 and prior

3.2 Vulnerability Overview

3.2.1 ACCESS OF RESOURCE USING INCOMPATIBLE TYPE (‘TYPE CONFUSION’) CWE-843

There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. For more details check the NVD link.

CVE-2023-0286 has been assigned to this vulnerability. A CVSS v3.1 base score of 7.4 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H).

3.2.2 USE AFTER FREE CWE-416

The public API function BIO

[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.

This article has been indexed from All CISA Advisories

Read the original article: