Remote Code Execution Vulnerability in Hitachi Energy RTU500 Product Line
CVE-2024-12169
8.7HIGH
Summary
A vulnerability in the RTU500 series by Hitachi Energy affects its IEC 60870-5-104 and IEC 61850 functionalities. If secure communication is enabled through IEC 62351-3 (TLS), the product may be susceptible to a specific attack sequence that can restart the affected communication module unit (CMU). This vulnerability necessitates immediate attention to reinforce cybersecurity measures and secure system configurations.
Affected Version(s)
RTU500 13.4.1 <= 13.4.4
RTU500 13.5.1 <= 13.5.3
RTU500 13.6.1
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved