Bypass Secure Update Vulnerability in RTU500
CVE-2024-2617
7.2HIGH
Summary
A vulnerability in the RTU500 series from Hitachi Energy enables authenticated and authorized users to circumvent secure firmware update mechanisms. This exploitation could allow an attacker to install unsigned firmware, potentially compromising system integrity and security. The vulnerability emphasizes the need for robust security measures to prevent unauthorized firmware modifications, especially in critical infrastructure contexts.
Affected Version(s)
RTU500 series CMU firmware 13.2.1 <= 13.2.7
RTU500 series CMU firmware 13.4.1 <= 13.4.4
RTU500 series CMU firmware 13.5.1 <= 13.5.3
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved