Hitachi ABB Power Grids has an update suggestion to handle an infinite loop vulnerability in its AFS Series, according to a report with CISA.

Successful exploitation of this vulnerability, which Hitachi ABB Power Grids self-reported, could cause a denial-of-service condition on one of the ports in a HSR ring.

Hitachi ABB Power Grids reports the vulnerability affects the following products in the AFS Series:

  • AFS660/AFS665 Version 7.0.07, including the following variants:
    — AFS660-SR
    — AFS665-SR

In the vulnerability, a crafted HSR frame can cause a denial-of-service condition on one of the ports in a HSR ring.

Schneider Bold

CVE-2020-9307 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.5.

The product sees use mainly in the energy sector, and on a global basis.

No known public exploits specifically target this vulnerability. This vulnerability is not exploitable remotely. However, an attacker with low skill level could leverage the issue.

Hitachi ABB Power Grids published an advisory for AFS Series and advises users to update products with available updates. The update removes the vulnerability by modifying the way the switch processes HSR frames.

For additional information and support, contact a product provider or Hitachi ABB Power Grids service organization. For contact information, click on Hitachi ABB Power Grids contact-centers.

ISSSource

Pin It on Pinterest

Share This