| CVE ID | CVSS Score | Severity | Description |
|---|---|---|---|
| CVE-2024-8176 | 6.5 | medium |
CVE-2024-8176. A stack overflow vulnerability exists in the libexpat library used by the IEC61850 functionality supported by REB500 product. An authenticated malicious user with local access could use a crafted IEC 61850 message to exploit the vulnerability in the libexpat library. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.
|
| CVE-2025-59375 | 6.5 | medium |
CVE-2025-59375. libexpat in Expat before 2.7.2 used by the IEC 61850 functionality supported by the REB500 product allows authenticated users to trigger large dynamic memory allocations via a small document that is submitted for parsing.
|
| Vendor | Product | Asset Type | Purdue Level | Firmware |
|---|---|---|---|---|
| Hitachi Energy | Unknown | rtu |
L1
|
12.2 |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | plc |
L1
|
-- |
| Siemens | Unknown | plc |
L1
|
-- |
| Siemens | Unknown | plc |
L1
|
-- |
| Siemens | Unknown | plc |
L1
|
-- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |