CVE-2022-2513 Details
Description
A vulnerability exists in the Intelligent Electronic Device (IED) Connectivity Package (ConnPack) credential storage function in Hitachi Energy’s PCM600 product included in the versions listed below, where IEDs credentials are stored in a cleartext format in the PCM600 database and logs files. An attacker having get access to the exported backup file can exploit the vulnerability and obtain user credentials of the IEDs. Additionally, an attacker with administrator access to the PCM600 host machine can obtain other user credentials by analyzing database log files. The credentials may be used to perform unauthorized modifications such as loading incorrect configurations, reboot the IEDs or cause a denial-of-service on the IEDs.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-312 | Cleartext Storage of Sensitive Information | [email protected] |
| CWE-312 | Cleartext Storage of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| hitachienergy 650connectivitypackage | 1.3.0 2.1.2 2.2.2 2.3.0 2.4.1 |
CPE
Remediation
| |
| hitachienergy 670connectivitypackage | 3.0.2 3.1.2 3.2.6 3.3.0 3.4.1 |
CPE
Remediation
| |
| hitachienergy gms600connectivitypackage | 1.3.0 1.3.1 |
CPE
Remediation
| |
| hitachienergy pcm600 | <= 2.11 |
CPE
Remediation
| |
| hitachienergy pwc600connectivitypackage | 1.1.0 1.1.1 1.1.2 1.2.0 1.3.0 |
CPE
Remediation
| |
| hitachienergy sam600ioconnectivitypackage | 1.0.0 1.1.0 1.2.0 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 28, 2024 | CVE Modified | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Dec 8, 2022 | Reanalysis | [email protected] |
| Nov 30, 2022 | Initial Analysis | [email protected] |