GMS600 TLS Sessions Exposed to Decryption Risk

The issue is not code execution in GMS600. It is a timing side channel in the OpenSSL component that can let an attacker recover the TLS pre-master secret and read application data sent over the connection. CISA maps CVE-2022-4304 to Hitachi Energy GMS600 versions 1.3.0 and 1.3.1. The advisory says an attacker who can send enough trial messages and measure response time may decrypt traffic protected by those sessions; Hitachi Energy lists version 1.3.2 as the fix. The exposed asset is transport confidentiality for TLS-protected OT or application traffic, not the HMI itself. Until updated or mitigated, traffic assumed to be private may be recoverable after repeated probing.

Part of the PlainSec briefing for 2026-05-21

Sources