IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Hitachi Energy REB500

MEDIUM
CVSS 6.5
Date 2026-10-06T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Hitachi Energy is aware of open-source software vulnerabilities that affect REB500 product versions listed in this document. These vulnerabilities can be exploited to carry out Denial of Service (DoS) attack on the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.

// Vulnerabilities (2)

CVE ID CVSS Score Severity Description
CVE-2024-8176 6.5 medium
CVE-2024-8176. A stack overflow vulnerability exists in the libexpat library used by the IEC61850 functionality supported by REB500 product. An authenticated malicious user with local access could use a crafted IEC 61850 message to exploit the vulnerability in the libexpat library. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.
CVE-2025-59375 6.5 medium
CVE-2025-59375. libexpat in Expat before 2.7.2 used by the IEC 61850 functionality supported by the REB500 product allows authenticated users to trigger large dynamic memory allocations via a small document that is submitted for parsing.

// Affected Products (21)

Vendor Product Asset Type Purdue Level Firmware
Hitachi Energy Unknown rtu
L1
12.2
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown plc
L1
--
Siemens Unknown plc
L1
--
Siemens Unknown plc
L1
--
Siemens Unknown plc
L1
--
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --

// Remediations (29)

Patch: Update to version 8.3.4.0
Update to version 8.3.4.0
Patch: See Section Additional Information.
See Section Additional Information.
Patch: Update to V3.2 or later version
Update to V3.2 or later version
Patch: Update to V3.2 or later version
Update to V3.2 or later version
Mitigation: Only build and run applications from trusted sources.
Only build and run applications from trusted sources.
Patch: Update to V3.1.5 or later version
Update to V3.1.5 or later version
Patch: Upgrade to version 2.2 when available
Upgrade to version 2.2 when available
Patch: Update to version 2.1 SP6 HF1
Update to version 2.1 SP6 HF1
Patch: Update to CMU Firmware version 13.7.8 or latest
Update to CMU Firmware version 13.7.8 or latest
Mitigation: Follow general mitigation factors/workarounds
Follow general mitigation factors/workarounds
Patch: Update to CMU Firmware version 13.8.2
Update to CMU Firmware version 13.8.2
Patch: Update to CMU Firmware version 12.7.8
Update to CMU Firmware version 12.7.8
Patch: Update to V3.2 or later version
Update to V3.2 or later version
Patch: See Section Additional Information.
See Section Additional Information.
Patch: Update to V3.2 or later version
Update to V3.2 or later version
Patch: Update to V3.1.5 or later version
Update to V3.1.5 or later version
Mitigation: Only build and run applications from trusted sources.
Only build and run applications from trusted sources.
Patch: Update to V3.3 or later version
Update to V3.3 or later version
Patch: Update to V3.3 or later version
Update to V3.3 or later version
Patch: See Section Additional Information.
See Section Additional Information.
Patch: Update to V3.3 or later version
Update to V3.3 or later version
Mitigation: Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel onl
Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.
Mitigation: Only build and run applications from trusted sources.
Only build and run applications from trusted sources.
Mitigation: Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel onl
Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.
Mitigation: Only build and run applications from trusted sources.
Only build and run applications from trusted sources.
Patch: Update to V3.3 or later version
Update to V3.3 or later version
Patch: Update to V3.3 or later version
Update to V3.3 or later version
Patch: See Section Additional Information.
See Section Additional Information.
Patch: Update to V3.3 or later version
Update to V3.3 or later version

// References