Hitachi Energy Rtu500 Series Cmu Firmware vulnerabilities
13 known vulnerabilities affecting hitachi_energy/rtu500_series_cmu_firmware.
Total CVEs
13
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH6MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2026-8065P2CRITICALCVSS 9.1≥ 9.0, < 12.02026-09-29
CVE-2026-8065 [CRITICAL] CWE-306 CVE-2026-8065: An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-
An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attacker to modify device functionality or compromise the integrity or availability of the device.
nvd
CVE-2026-8066P2CRITICALCVSS 9.1≥ 9.0, < 12.02026-09-29
CVE-2026-8066 [CRITICAL] CWE-23 CVE-2026-8066: A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of
A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful exploitation could result in unauthorized modification of device data or disruption of the de
nvd
CVE-2022-2081P3HIGHCVSS 7.5≥ 12.0.1.0, ≤ 12.0.13.0≥ 12.2.1.0, ≤ 12.2.11.0+5 more2024-01-04
CVE-2022-2081 [HIGH] CWE-787 CVE-2022-2081: A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above.
A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is enabled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500 in a high rate, causing the targeted RTU500 CMU to reboot. The vulnerability is caused by a lack of flood co
nvd
CVE-2024-2617P3HIGHCVSS 7.2≥ 13.2.1, ≤ 13.2.7≥ 13.4.1, ≤ 13.4.4+1 more2024-04-30
CVE-2024-2617 [HIGH] CWE-358 CVE-2024-2617: A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass se
A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update,
if secure update feature was not enabled on all
CMUs of a RTU500. If a
malicious actor successfully exploits this vulnerability, they
could use it to update the RTU500 with unsigned firmware.
nvd
CVE-2022-28613P3HIGHCVSS 7.5v12.0.*v12.2.*+4 more2022-05-02
CVE-2022-28613 [HIGH] CWE-1284 CVE-2022-28613: A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above.
A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is en-abled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500, causing the receiving RTU500 CMU to reboot. The vulnerability is caused by the validation error in the
nvd
CVE-2023-6711P3HIGHCVSS 7.5≥ 12.0.1, ≤ 12.0.14≥ 12.2.1, ≤ 12.2.11+6 more2023-12-19
CVE-2023-6711 [HIGH] CWE-120 CVE-2023-6711: Vulnerability exists in SCI IEC 60870-5-104 and HCI IEC 60870-5-104 that affects the RTU500 series p
Vulnerability exists in SCI IEC 60870-5-104 and HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Specially crafted messages sent to the mentioned components are not validated properly and can result in buffer overflow and as final consequence to a reboot of an RTU500 CMU.
nvd
CVE-2026-1773P3HIGHCVSS 7.5≥ 12.7.1, ≤ 12.7.7≥ 13.5.1, ≤ 13.5.4+3 more2026-02-24
CVE-2026-1773 [HIGH] CWE-184 CVE-2026-1773: IEC 60870-5-104 used in RTU500: Potential Denial of Service impact on reception of invalid U-format
IEC 60870-5-104 used in RTU500: Potential Denial of Service impact on reception of invalid U-format frame. Product is only affected if IEC 60870-5-104 bi-directional functionality is configured. Enabling secure communication following IEC 62351-3 does not remediate the vulnerability but mitigates the risk of exploitation.
nvd
CVE-2024-1531P3HIGHCVSS 8.2≥ 12.0.1, ≤ 12.0.14≥ 12.2.1, ≤ 12.2.11+6 more2024-03-27
CVE-2024-1531 [HIGH] CWE-434 CVE-2024-1531: A vulnerability exists in the stb-language file handling that affects the RTU500 series product vers
A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could print random memory content in the RTU500 system log, if an authorized user uploads a specially crafted stb-language file.
nvd
CVE-2026-8067P3MEDIUMCVSS 6.5≥ 9.0, < 12.02026-09-29
CVE-2026-8067 [MEDIUM] CWE-862 CVE-2026-8067: An improper authorization vulnerability in the end-of-life versions of RTU500’s web application allo
An improper authorization vulnerability in the end-of-life versions of RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset endpoint. Successful exploitation could cause temporary device unavailability and disruption of its intended operation.
nvd
CVE-2024-1532P4MEDIUMCVSS 6.8≥ 12.0.1, ≤ 12.0.14≥ 12.2.1, ≤ 12.2.11+6 more2024-03-27
CVE-2024-1532 [MEDIUM] CWE-434 CVE-2024-1532: A vulnerability exists in the stb-language file handling that affects the RTU500 series product vers
A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could enforce diagnostic texts being displayed as empty strings, if an authorized user uploads a specially crafted stb-language file.
nvd
CVE-2026-1772P4MEDIUMCVSS 5.3≥ 12.7.1, ≤ 12.7.7≥ 13.5.1, ≤ 13.5.4+3 more2026-02-24
CVE-2026-1772 [MEDIUM] CWE-280 CVE-2026-1772: RTU500 web interface: An unprivileged user can read user management information. The information can
RTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via the RTU500 web user interface but requires further tools like browser development utilities to access them without required privileges.
nvd
CVE-2026-8479P4MEDIUMCVSS 6.9≥ 12.7.1, ≤ 12.7.7≥ 13.5.1, ≤ 13.5.4+3 more2026-05-26
CVE-2026-8479 [MEDIUM] CWE-476 CVE-2026-8479: IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing,
IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable
for a NULL pointer dereferencing, if a specially crafted
sequence of messages is sent for a certain time, causing
Denial of Service impact.
Product is only affected if IEC 60870-5-104 functionality in
bidirectional mode (BCI) is configured.
nvd
CVE-2026-17539P4MEDIUMCVSS 5.9≥ 12.7.1, ≤ 12.7.7≥ 13.5.1, ≤ 13.5.4+3 more2026-09-03
CVE-2026-17539 [MEDIUM] CWE-476 CVE-2026-17539: RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short interval
RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry of the enhanced message queue. This can cause a BCI_IEC104 fatal write error, resulting in connection interruption and restart, and ultimately a denial of service for bidirectional IEC 60870-5-
nvd