CISA warns of CVE-2022-4304 in industrial grid management systems that could allow attackers to decrypt TLS connections through timing-based side channel attacks.
- Hitachi Energy GMS600 versions 1.3.0 to 1.3.1 contain OpenSSL vulnerability CVE-2022-4304
- Attackers could exploit timing differences to recover TLS pre-master secrets and decrypt connections
- The flaw affects critical manufacturing infrastructure deployed worldwide
The US Cybersecurity and Infrastructure Security Agency has issued an advisory warning that Hitachi Energy’s GMS600 grid management system contains a timing-based vulnerability in its OpenSSL implementation that could allow attackers to decrypt encrypted network communications.
The vulnerability, tracked as CVE-2022-4304, affects GMS600 versions 1.3.0 through 1.3.1. CISA rates the vulnerability with a CVSS score of 5.9, categorising it as medium severity.
The flaw exists in the OpenSSL RSA decryption implementation and creates a timing-based side channel that could be exploited in Bleichenbacher-style attacks. An attacker would need to send a very large number of trial messages to a target server and measure the time taken to process each one.
According to CISA’s advisory, after collecting sufficient timing data, an attacker could recover the pre-master secret used in the original TLS connection. This would enable them to decrypt application data sent over that connection.
The vulnerability affects all RSA padding modes including PKCS#1 v1.5, RSA-OEAP and RSASVE. In typical TLS connections, RSA is commonly used by clients to send encrypted pre-master secrets to servers during the handshake process.
Hitachi Energy’s GMS600 is used in critical manufacturing infrastructure and is deployed worldwide. The system’s Swiss-based manufacturer has acknowledged the vulnerability and is working on mitigation measures, though specific remediation steps were not detailed in the advisory.
This represents another example of legacy OpenSSL vulnerabilities affecting industrial control systems, highlighting the ongoing challenge of securing third-party components in critical infrastructure.
Why It Matters
For CISOs overseeing critical infrastructure or manufacturing environments, this vulnerability represents a significant concern given the widespread deployment of affected GMS600 systems. The ability to decrypt TLS communications could expose sensitive operational data and potentially enable lateral movement within industrial networks.
While the attack requires substantial resources and time to execute successfully, the targeting of industrial control systems makes this a priority for organisations in the critical manufacturing sector. Board reporting should emphasise the intersection of legacy component vulnerabilities with operational technology security.
What To Do Now
- Identify all Hitachi Energy GMS600 systems running versions 1.3.0 to 1.3.1 in your environment
- Review network segmentation to limit exposure of affected systems per CISA’s advisory
- Monitor for available patches or mitigation guidance from Hitachi Energy
- Implement additional network monitoring for unusual traffic patterns to affected systems
