The issue is not code execution in GMS600. It is a timing side channel in the OpenSSL component that can let an attacker recover the TLS pre-master secret and read application data sent over the connection.
CISA maps CVE-2022-4304 to Hitachi Energy GMS600 versions 1.3.0 and 1.3.1. The advisory says an attacker who can send enough trial messages and measure response time may decrypt traffic protected by those sessions; Hitachi Energy lists version 1.3.2 as the fix.
The exposed asset is transport confidentiality for TLS-protected OT or application traffic, not the HMI itself. Until updated or mitigated, traffic assumed to be private may be recoverable after repeated probing.
CVSS 5.9 MEDIUM: a timing based side channel exists in the OpenSSL RSA Decryption implementation
which could be sufficient to recover a plaintext across a network in a
Bleichenbacher style attack. EPSS 16% (97th percentile), up from 0.2%.
Hitachi Energy GMS600 Summary Hitachi Energy is aware of the vulnerability, CVE-2022-4304 in the OSS component OpenSSL, that affects the GMS600 versions that are listed below.