Hitachi Energy Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Hitachi Energy products.
Products
- FOXMAN-UN15 vulnerabilities
- UNEM15 vulnerabilities
- MicroSCADA X SYS60014 vulnerabilities
- RTU500 series CMU firmware9 vulnerabilities
- RTU5007 vulnerabilities
- SDM6007 vulnerabilities
- MicroSCADA Pro SYS6005 vulnerabilities
- FOX61x4 vulnerabilities
- RTU500 series4 vulnerabilities
- Asset Suite3 vulnerabilities
- eSOMS3 vulnerabilities
- MicroSCADA SYS6003 vulnerabilities
- MSM3 vulnerabilities
- TRMTracker3 vulnerabilities
- TropOS 4th Gen3 vulnerabilities
- TXpert Hub CoreTec 4 version3 vulnerabilities
- GMS6002 vulnerabilities
- MACH System Software2 vulnerabilities
- NSD570 Teleprotection Equipment2 vulnerabilities
- PCM6002 vulnerabilities
- PWC6002 vulnerabilities
- Relion 670 Series2 vulnerabilities
- Relion 670/650 and SAM600-IO2 vulnerabilities
- Relion 670/650 Series2 vulnerabilities
- Relion 670/650/SAM600-IO2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-10763HIGH | Generated title:Hitachi Energy PROMOD V Reliance on HTTP instead of HTTPSPROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support from 3rd party Digipede server. CWE-1428Jun 30, 2026 | CVSS7.0v4.0 | EPSS0.253% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8479MEDIUM | Generated title:Hitachi Energy RTU500 Series CMU Firmware IEC 60870-5-104 NULL Pointer Dereference Denial of ServiceIEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially crafted sequence of messages is sent for a certain time, causing Denial of Service impact. Product is only affected if IEC 60870-5-104 functionality in bidirectional mode (BCI) is configured. CWE-476May 26, 2026 | CVSS6.9v4.0 | EPSS0.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-7310MEDIUM | Generated title:Hitachi Energy MACH HiDraw XML Parser Heap-based Buffer OverflowA heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious user with local access can exploit this vulnerability using a specially crafted XML file which may lead to memory corruption and potential arbitrary code execution. Successful exploitation could result in application crashes (denial of service) and compromise the confidentiality and integrity of the affected system. CWE-122May 26, 2026 | CVSS4.4v4.0 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2460HIGH | Generated title:Hitachi Energy Relion REB500 Privilege Escalation via DAC ProtocolA vulnerability exists in REB500 for an authenticated user with low-level privileges to access and alter the content of directories by using the DAC protocol that the user is not authorized to do so. CWE-267Feb 24, 2026 | CVSS7.6v4.0 | EPSS0.278% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2459HIGH | Generated title:Hitachi Energy Relion REB500 Installer Role Unauthorized Directory AccessA vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of directories that the role is not authorized to do so. CWE-267Feb 24, 2026 | CVSS7.4v4.0 | EPSS0.33% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-1773HIGH | Generated title:Hitachi Energy RTU500 Series CMU Firmware Denial of Service via Invalid IEC 60870-5-104 U-Format FrameIEC 60870-5-104 used in RTU500: Potential Denial of Service impact on reception of invalid U-format frame. Product is only affected if IEC 60870-5-104 bi-directional functionality is configured. Enabling secure communication following IEC 62351-3 does not remediate the vulnerability but mitigates the risk of exploitation. CWE-184Feb 24, 2026 | CVSS8.7v4.0 | EPSS0.411% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-1772MEDIUM | Generated title:Hitachi Energy RTU500 Series CMU Firmware Improper Handling of Insufficient PermissionsRTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via the RTU500 web user interface but requires further tools like browser development utilities to access them without required privileges. CWE-280Feb 24, 2026 | CVSS5.3v4.0 | EPSS0.26% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-7740HIGH | Use of default credentials vulnerability in Hitachi Energy SuprOS productDefault credentials vulnerability exists in SuprOS product. If exploited, this could allow an authenticated local attacker to use an admin account created during product deployment. CWE-1392Jan 28, 2026 | CVSS8.8v4.0 | EPSS0.177% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-1038HIGH | The “Diagnostics Tools” page of the web-based configuration utility does not properly validate user-controlled input, allowing an authenticated user with high privileges to inject commands into the command shell of the TropOS 4th Gen device. The injected commands can be exploited to execute several set-uid (SUID) applications to ultimately gain root access to the TropOS device. CWE-78Oct 28, 2025 | CVSS7.5v4.0 | EPSS0.298% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-1037HIGH | By making minor configuration changes to the TropOS 4th Gen device, an authenticated user with the ability to run user level shell commands can enable access via secure shell (SSH) to an unrestricted root shell. This is possible through abuse of a particular set of scripts and executables that allow for certain commands to be run as root from an unprivileged context. CWE-269Oct 28, 2025 | CVSS7.5v4.0 | EPSS0.142% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-1036HIGH | Command injection vulnerability exists in the “Logging” page of the web-based configuration utility. An authenticated user with low privileged network access for the configuration utility can execute arbitrary commands on the underlying OS to obtain root SSH access to the TropOS 4th Gen device. CWE-78Oct 28, 2025 | CVSS8.7v4.0 | EPSS1.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-10217MEDIUM | A vulnerability exists in Asset Suite for an authenticated user to manipulate the content of performance related log data or to inject crafted data in logfile for potentially carrying out further malicious attacks. Performance logging is typically enabled for troubleshooting purposes while resolving application performance related issues. CWE-117Sep 30, 2025 | CVSS6.0v4.0 | EPSS0.277% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-39205HIGH | A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol allows remote Man-in-the-Middle attack due to missing proper validation. CWE-295Jun 24, 2025 | CVSS7.1v4.0 | EPSS0.177% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-39204HIGH | A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, so returning data can leak unauthorized information to the user. CWE-200Jun 24, 2025 | CVSS8.5v4.0 | EPSS0.318% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-39203HIGH | A vulnerability exists in the IEC 61850 of the MicroSCADA X SYS600 product. An IEC 61850-8 crafted message content from IED or remote system can cause a denial of service resulting in disconnection loop. CWE-354Jun 24, 2025 | CVSS7.1v4.0 | EPSS0.202% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-39202HIGH | A vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with low privileges can see and overwrite files causing information leak and data corruption. CWE-269Jun 24, 2025 | CVSS8.3v4.0 | EPSS0.211% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-39201MEDIUM | A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to tamper a system file, making denial of Notify service. CWE-276Jun 24, 2025 | CVSS6.9v4.0 | EPSS0.121% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-2403HIGH | A denial-of-service vulnerability due to improper prioritization of network traffic over protection mechanism exists in Relion 670/650 and SAM600-IO series device that if exploited could potentially cause critical functions like LDCM (Line Distance Communication Module) to malfunction. CWE-770Jun 24, 2025 | CVSS8.7v4.0 | EPSS0.316% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-1718HIGH | An authenticated user with file access privilege via FTP access can cause the Relion 670/650 and SAM600-IO series device to reboot due to improper disk space management. CWE-754Jun 24, 2025 | CVSS7.1v4.0 | EPSS0.354% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-2500CRITICAL | A vulnerability exists in the SOAP Web services of the Asset Suite versions listed below. If successfully exploited, an attacker could gain unauthorized access to the product and the time window of a possible password attack could be expanded. CWE-256May 30, 2025 | CVSS9.1v4.0 | EPSS0.335% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-1484MEDIUM | A vulnerability exists in the media upload component of the Asset Suite versions listed below. If successfully exploited an attacker could impact the confidentiality or integrity of the system. An attacker can use this vulnerability to construct a request that will cause JavaScript code supplied by the attacker to execute within the user’s browser in the context of that user’s session with the application. CWE-184May 30, 2025 | CVSS6.3v4.0 | EPSS0.196% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-27631MEDIUM | The TRMTracker web application is vulnerable to LDAP injection attack potentially allowing an attacker to inject code into a query and execute remote commands that can read and update data on the website. CWE-90Mar 25, 2025 | CVSS6.5v3.1 | EPSS0.254% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-27633MEDIUM | The TRMTracker web application is vulnerable to reflected Cross-site scripting attack. The application allows client-side code injection that might be used to compromise the confidentiality and integrity of the system. CWE-79Mar 25, 2025 | CVSS6.1v3.1 | EPSS0.231% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-1445HIGH | A vulnerability exists in RTU IEC 61850 client and server functionality that could impact the availability if renegotiation of an open IEC61850 TLS connection takes place in specific timing situations, when IEC61850 communication is active. Precondition is that IEC61850 as client or server are configured using TLS on RTU500 device. It affects the CMU the IEC61850 stack is configured on. CWE-820Mar 25, 2025 | CVSS8.7v4.0 | EPSS0.309% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-27632MEDIUM | A Host Header Injection vulnerability in TRMTracker application may allow an attacker by modifying the host header value in an HTTP request to leverage multiple attack vectors, including defacing the site content through web-cache poisoning. | CVSS6.1v3.1 | EPSS0.231% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |