Hitachi Energy Vulnerabilities and Affected Products
Vulnerabilities associated with RTU500 series CMU firmware.
Products
Clear product- FOXMAN-UN15 vulnerabilities
- UNEM15 vulnerabilities
- MicroSCADA X SYS60014 vulnerabilities
- RTU500 series CMU firmware9 vulnerabilities
- RTU5007 vulnerabilities
- SDM6007 vulnerabilities
- MicroSCADA Pro SYS6005 vulnerabilities
- FOX61x4 vulnerabilities
- RTU500 series4 vulnerabilities
- Asset Suite3 vulnerabilities
- eSOMS3 vulnerabilities
- MicroSCADA SYS6003 vulnerabilities
- MSM3 vulnerabilities
- TRMTracker3 vulnerabilities
- TropOS 4th Gen3 vulnerabilities
- TXpert Hub CoreTec 4 version3 vulnerabilities
- GMS6002 vulnerabilities
- MACH System Software2 vulnerabilities
- NSD570 Teleprotection Equipment2 vulnerabilities
- PCM6002 vulnerabilities
- PWC6002 vulnerabilities
- Relion 670 Series2 vulnerabilities
- Relion 670/650 and SAM600-IO2 vulnerabilities
- Relion 670/650 Series2 vulnerabilities
- Relion 670/650/SAM600-IO2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-8479MEDIUM | Generated title:Hitachi Energy RTU500 Series CMU Firmware IEC 60870-5-104 NULL Pointer Dereference Denial of ServiceIEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially crafted sequence of messages is sent for a certain time, causing Denial of Service impact. Product is only affected if IEC 60870-5-104 functionality in bidirectional mode (BCI) is configured. CWE-476May 26, 2026 | CVSS6.9v4.0 | EPSS0.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-1773HIGH | Generated title:Hitachi Energy RTU500 Series CMU Firmware Denial of Service via Invalid IEC 60870-5-104 U-Format FrameIEC 60870-5-104 used in RTU500: Potential Denial of Service impact on reception of invalid U-format frame. Product is only affected if IEC 60870-5-104 bi-directional functionality is configured. Enabling secure communication following IEC 62351-3 does not remediate the vulnerability but mitigates the risk of exploitation. CWE-184Feb 24, 2026 | CVSS8.7v4.0 | EPSS0.411% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-1772MEDIUM | Generated title:Hitachi Energy RTU500 Series CMU Firmware Improper Handling of Insufficient PermissionsRTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via the RTU500 web user interface but requires further tools like browser development utilities to access them without required privileges. CWE-280Feb 24, 2026 | CVSS5.3v4.0 | EPSS0.26% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-2617HIGH | A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if secure update feature was not enabled on all CMUs of a RTU500. If a malicious actor successfully exploits this vulnerability, they could use it to update the RTU500 with unsigned firmware. CWE-358Apr 30, 2024 | CVSS7.2v3.1 | EPSS0.666% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-1532MEDIUM | A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could enforce diagnostic texts being displayed as empty strings, if an authorized user uploads a specially crafted stb-language file. CWE-434Mar 27, 2024 | CVSS6.8v3.1 | EPSS0.568% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-1531HIGH | A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could print random memory content in the RTU500 system log, if an authorized user uploads a specially crafted stb-language file. CWE-434Mar 27, 2024 | CVSS8.2v3.1 | EPSS0.448% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-2081HIGH | A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is enabled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500 in a high rate, causing the targeted RTU500 CMU to reboot. The vulnerability is caused by a lack of flood control which eventually if exploited causes an internal stack overflow in the HCI Modbus TCP function. | CVSS7.5v3.1 | EPSS0.636% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-6711MEDIUM | Vulnerability exists in SCI IEC 60870-5-104 and HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Specially crafted messages sent to the mentioned components are not validated properly and can result in buffer overflow and as final consequence to a reboot of an RTU500 CMU. | CVSS5.9v3.1 | EPSS0.669% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-28613HIGH | Specially Crafted Modbus TCP Packet Vulnerability in RTU500 seriesA vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is en-abled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500, causing the receiving RTU500 CMU to reboot. The vulnerability is caused by the validation error in the length information carried in MBAP header in the HCI Modbus TCP function. | CVSS7.5v3.1 | EPSS0.951% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |