Le sessioni TLS di GMS600 esposte a rischio di decrittazione
Il problema non è l'esecuzione di codice in GMS600. È un side channel temporale nel componente OpenSSL che può consentire a un attaccante di recuperare il pre-master secret TLS e leggere i dati applicativi inviati sulla connessione.
CVSS 5.9 MEDIUM: a timing based side channel exists in the OpenSSL RSA Decryption implementation
which could be sufficient to recover a plaintext across a network in a
Bleichenbacher style attack. EPSS 16% (97º percentile), in aumento rispetto a 0.2%.
Hitachi Energy GMS600 Summary Hitachi Energy is aware of the vulnerability, CVE-2022-4304 in the OSS component OpenSSL, that affects the GMS600 versions that are listed below.