CVE-2024-2617
published 2024-04-30CVE-2024-2617: A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if secure update feature was not enabled on…
PriorityP343high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.67%
50.4th percentile
A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update,
if secure update feature was not enabled on all
CMUs of a RTU500. If a
malicious actor successfully exploits this vulnerability, they
could use it to update the RTU500 with unsigned firmware.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hitachi_energy | rtu500_series_cmu_firmware | 13.2.1 – 13.2.7 | — |
| hitachi_energy | rtu500_series_cmu_firmware | 13.4.1 – 13.4.4 | — |
| hitachi_energy | rtu500_series_cmu_firmware | 13.5.1 – 13.5.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Hitachi Energy RTU500 Series Product (Update B)
cisa_ics·2026-03-03·CVSS 7.2
CVE-2024-2617 [HIGH] Hitachi Energy RTU500 Series Product (Update B)
ICS Advisory
##
Hitachi Energy RTU500 Series Product (Update B)
Last RevisedMarch 03, 2026
Alert CodeICSA-25-023-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Hitachi Energy is aware of the vulnerability CVE-2024-2617 in the RTU500 Web server component, that affects the RTU500 versions that are listed below. An attacker successfully exploiting this vulnerability could bypass secure update. Please refer to the Recommended Immediate Actions for information about the available mitigation/remediation strategies.
The following versions of Hitachi Energy RTU500 Series Product are affected:
- RTU500 series CMU Firmware vers:RTU500_series_CMU_Firmware/>=13.2.1|=13.4.1|=13.5.1|<=13.5.3
CVSS
Vendor
Equi
GHSA
GHSA-8rv2-8c5x-g54v: A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update
ghsa_unreviewed·2024-04-30
CVE-2024-2617 [HIGH] CWE-358 GHSA-8rv2-8c5x-g54v: A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update
A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update. If a
malicious actor successfully exploits this vulnerability, they
could use it to update the RTU500 with unsigned firmware.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-04-30
Published