CVE-2023-1514
Last modified
CVE-2023-1514 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A vulnerability exists in the component RTU500 Scripting interface. When a client connects to a server using TLS, the server presents a certificate. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
A vulnerability exists in the component RTU500 Scripting interface. When a client connects to a server using TLS, the server presents a certificate. This certificate links a public key to the identity of the service and is signed by a Certification Authority (CA), allowing the client to validate that the remote service can be trusted and is not malicious. If the client does not validate the parameters of the certificate, then attackers could be able to spoof the identity of the service. An attacker could exploit the vulnerability by using faking the identity of a RTU500 device and intercepting the messages initiated via the RTU500 Scripting interface.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hitachienergy | Rtu500 Scripting Interface | 1.0.1.30 |
| Hitachienergy | Rtu500 Scripting Interface | 1.0.2 |
| Hitachienergy | Rtu500 Scripting Interface | 1.1.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-1514?
How severe is CVE-2023-1514?
How do I fix CVE-2023-1514?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-1505A vulnerability, which was classified as critical, has been …8.1
- CVE-2023-1506A vulnerability, which was classified as critical, was found…8.1
- CVE-2023-1507A vulnerability has been found in SourceCodester E-Commerce …6.1
- CVE-2023-1508Improper Neutralization of Special Elements used in an SQL C…9.8
- CVE-2023-1509The GMAce plugin for WordPress is vulnerable to Cross-Site R…8.8
- CVE-2023-1513A flaw was found in KVM. When calling the KVM_GET_DEBUGREGS …3.3
- CVE-2023-1515Cross-site Scripting (XSS) - Stored in GitHub repository pim…5.4
- CVE-2023-1516RoboDK versions 5.5.3 and prior contain an insecure permissi…7.8
- CVE-2023-1517Cross-site Scripting (XSS) - DOM in GitHub repository pimcor…4.8
- CVE-2023-1518CP Plus KVMS Pro versions 2.01.0.T.190521 and prior are vuln…7.5
- CVE-2023-1521On Linux the sccache client can execute arbitrary code with …7.8
- CVE-2023-1522SQL Injection in the Hardware Inventory report of Security C…8.8
Are you affected by CVE-2023-1514?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
