CVE Feed

    Dashboard / CVE / CVE-2022-2081

    CVE-2022-2081

    A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is enabled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500 in a high rate, causing the targeted RTU500 CMU to reboot. The vulnerability is caused by a lack of flood control which eventually if exploited causes an internal stack overflow in the HCI Modbus TCP function.

    Published:Jan 4, 2024
    Last Modified:May 22, 2025
    EPS:Jan 4, 2024
    EPSS Score:0.00155
    CVSS Score:7.5

    Affected Products

    Vendor
    Hitachienergy
    Product
    Rtu520
    Vendor
    Hitachienergy
    Product
    Rtu520 Firmware
    Vendor
    Hitachienergy
    Product
    Rtu530
    Vendor
    Hitachienergy
    Product
    Rtu530 Firmware
    Vendor
    Hitachienergy
    Product
    Rtu540
    Vendor
    Hitachienergy
    Product
    Rtu540 Firmware
    Vendor
    Hitachienergy
    Product
    Rtu560
    Vendor
    Hitachienergy
    Product
    Rtu560 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High