PatchSiren cyber security CVE debrief
CVE-2023-0216 Hitachi Energy CVE debrief
CVE-2023-0216 is a denial-of-service issue affecting Hitachi Energy PCU400 and PCULogger when vulnerable OpenSSL PKCS7 parsing functions are used on malformed data. The advisory states that an invalid pointer dereference on read can crash the application. Hitachi Energy’s guidance focuses on updating affected releases used with IEC62351-3 secure IEC104/DNP3 deployments.
- Vendor
- Hitachi Energy
- Product
- PCU400
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-02-25
- Original CVE updated
- 2025-02-25
- Advisory published
- 2025-02-25
- Advisory updated
- 2025-02-25
Who should care
Operators and maintainers of Hitachi Energy PCU400 and PCULogger, especially environments using IEC62351-3 secure IEC104/DNP3 functionality. Security teams responsible for OT asset inventories, patch management, and application hardening should prioritize review.
Technical summary
The issue is described as an invalid pointer dereference on read triggered by malformed PKCS7 data passed to d2i_PKCS7(), d2i_PKCS7_bio(), or d2i_PKCS7_fp(). The result is an application crash, creating a denial-of-service condition. The advisory notes that OpenSSL’s TLS implementation does not call these functions, but third-party applications may invoke them on untrusted data.
Defensive priority
High for exposed or operationally important OT deployments, because the flaw can cause an application crash and the affected products support industrial communication use cases. Prioritize systems that use the impacted versions and secure IEC104/DNP3 features.
Recommended defensive actions
- Update PCU400 to version 6.6.0 or later when IEC62351-3 secure for IEC104/DNP3 is used.
- Update PCU400 to version 9.4.2 or later when IEC62351-3 secure for IEC104/DNP3 is used.
- If PCULogger is used, plan to update to version 1.2.0 or later when available; it is noted as compatible with PCU400 9.4.2 and later.
- Inventory OT systems for any third-party software that may call OpenSSL PKCS7 parsing functions on untrusted input.
- Reduce exposure to untrusted inputs and follow CISA industrial control system defensive guidance for segmentation, least privilege, and defense in depth.
Evidence notes
The source CSAF advisory identifies Hitachi Energy PCU400 and PCULogger as affected products and describes the crash condition from malformed PKCS7 data. It also lists the vendor remediation guidance and links to the vendor advisory and CISA advisory. CVSS is 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), supporting a high availability-focused priority.
Official resources
-
CVE-2023-0216 CVE record
CVE.org
-
CVE-2023-0216 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
Public advisory published by CISA on 2025-02-25 with the same date in the provided source metadata. The CVE record is identified as CVE-2023-0216, but the supplied advisory publication date is 2025-02-25 and should be used for timeline anch