NULL Pointer Dereference Vulnerability in RTU500 from Hitachi Energy
CVE-2026-17539
5.9MEDIUM
What is CVE-2026-17539?
The RTU500 device manufactured by Hitachi Energy is susceptible to a NULL pointer dereference vulnerability under high-load conditions. Specifically, when GI requests are sent at short intervals, the enhanced message queue can experience a critical failure. This leads to a BCI_IEC104 fatal write error, which interrupts the connection and potentially restarts the system, resulting in a denial of service for bidirectional IEC 60870-5-104 communication, impacting operational continuity.
Affected Version(s)
RTU500 series CMU firmware 12.7.1 <= 12.7.7
RTU500 series CMU firmware 13.5.1 <= 13.5.4
RTU500 series CMU firmware 13.6.1 <= 13.6.3