PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-0216 Hitachi Energy CVE debrief

CVE-2023-0216 is a denial-of-service issue affecting Hitachi Energy PCU400 and PCULogger when vulnerable OpenSSL PKCS7 parsing functions are used on malformed data. The advisory states that an invalid pointer dereference on read can crash the application. Hitachi Energy’s guidance focuses on updating affected releases used with IEC62351-3 secure IEC104/DNP3 deployments.

Vendor
Hitachi Energy
Product
PCU400
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2023-11-14
Original CVE updated
2024-03-12
Advisory published
2023-11-14
Advisory updated
2024-03-12

Who should care

Operators and maintainers of Hitachi Energy PCU400 and PCULogger, especially environments using IEC62351-3 secure IEC104/DNP3 functionality. Security teams responsible for OT asset inventories, patch management, and application hardening should prioritize review.

Technical summary

The issue is described as an invalid pointer dereference on read triggered by malformed PKCS7 data passed to d2i_PKCS7(), d2i_PKCS7_bio(), or d2i_PKCS7_fp(). The result is an application crash, creating a denial-of-service condition. The advisory notes that OpenSSL’s TLS implementation does not call these functions, but third-party applications may invoke them on untrusted data.

Defensive priority

High for exposed or operationally important OT deployments, because the flaw can cause an application crash and the affected products support industrial communication use cases. Prioritize systems that use the impacted versions and secure IEC104/DNP3 features.

Recommended defensive actions

  • Update PCU400 to version 6.6.0 or later when IEC62351-3 secure for IEC104/DNP3 is used.
  • Update PCU400 to version 9.4.2 or later when IEC62351-3 secure for IEC104/DNP3 is used.
  • If PCULogger is used, plan to update to version 1.2.0 or later when available; it is noted as compatible with PCU400 9.4.2 and later.
  • Inventory OT systems for any third-party software that may call OpenSSL PKCS7 parsing functions on untrusted input.
  • Reduce exposure to untrusted inputs and follow CISA industrial control system defensive guidance for segmentation, least privilege, and defense in depth.

Evidence notes

The source CSAF advisory identifies Hitachi Energy PCU400 and PCULogger as affected products and describes the crash condition from malformed PKCS7 data. It also lists the vendor remediation guidance and links to the vendor advisory and CISA advisory. CVSS is 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), supporting a high availability-focused priority.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-0216 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-0216

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-0216 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-0216

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-065-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-065-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.