IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Hitachi Energy RTU500 Series

HIGH
CVSS 7.5
Date 2026-10-08T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Hitachi Energy is aware of multiple vulnerabilities that affect the RTU500 versions that are listed below. An attacker successfully exploiting these vulnerabilities could potentially cause Denial of Service (DoS) impact on RTU500. Please refer to the Recommended Immediate Actions for information about the available mitigation/remediation strategies.

// Vulnerabilities (7)

CVE ID CVSS Score Severity Description
CVE-2024-45492 6.5 medium
CVE-2024-45492. A vulnerability has been identified in libexpat library used in the IEC 61850 client and server components of the RTU500 product series. An authenticated and authorized malicious user could load a crafted XML input which leads to an integer overflow potentially causing RTU500 to reboot.
CVE-2024-28757 6.5 medium
CVE-2024-28757. A vulnerability has been identified in libexpat library used in the IEC 61850 client and server components of the RTU500 product series. An authenticated and authorized malicious user could load a crafted XML input which may lead to a memory mismanagement potentially causing RTU500 to reboot.
CVE-2024-45491 6.5 medium
CVE-2024-45491. A vulnerability has been identified in libexpat library used in the IEC 61850 client and server components of the RTU500 product series. An authenticated and authorized malicious user could load a crafted XML input which may lead to heap corruption potentially causing RTU500 to reboot.
CVE-2024-45490 6.5 medium
CVE-2024-45490. A vulnerability has been identified in the libexpat library used in IEC 61850 client and server components of the RTU500 product series. An authenticated and authorized malicious user could load a crafted XML input which may lead to memory mismanagement potentially causing RTU500 to reboot.
CVE-2023-2953 7.5 high
CVE-2023-2953. A vulnerability has been identified in the openLDAP library used in Central Account Management (CAM) client. This issue can lead to a Denial of Service (DoS) condition when a specially crafted request may cause a null pointer to deference, resulting in affected CMU to automatically recovering itself by rebooting.
CVE-2025-39203 4.3 medium
CVE-2025-39203. A vulnerability exists in the IEC 61850 protocol of the RTU500 product series. An IEC 61850-8 crafted message content from a device (e.g. an IED) or remote system can cause a Denial of Service (DoS) resulting in disconnection of the device to the RTU500 until next reboot.
CVE-2025-6021 6.5 medium
CVE-2025-6021. A vulnerability exists in libxml library used by RTU500 Web server functionality. An authenticated and authorized malicious user could send a crafted XML message which may lead to buffer overflow potentially causing RTU500 to reboot.

// Affected Products (20)

Vendor Product Asset Type Purdue Level Firmware
Hitachi Energy Unknown rtu
L1
12.2
Siemens Unknown network_device -- --
Siemens Unknown plc
L1
--
Siemens Unknown plc
L1
--
Siemens Unknown plc
L1
--
Siemens Unknown plc
L1
--
Hitachi Energy Unknown rtu
L1
13.6.1
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Hitachi Energy Unknown scada_server
L2
--
Hitachi Energy Unknown scada_server
L2
--

// Remediations (35)

Patch: Update to V3.1 or later version
Update to V3.1 or later version
Mitigation: Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel onl
Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.
Mitigation: Only build and run applications from trusted sources.
Only build and run applications from trusted sources.
Mitigation: Only build and run applications from trusted sources.
Only build and run applications from trusted sources.
Mitigation: Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel onl
Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.
Patch: Update to V3.1 or later version
Update to V3.1 or later version
Mitigation: Subnet Solutions inc. reports that dependencies have been updated and vulnerabilities are to be addr
Subnet Solutions inc. reports that dependencies have been updated and vulnerabilities are to be addressed in PowerSYSTEM Center 2020 Update 23 release.
Mitigation: Apply application allow-listing to prevent unauthorized executables from running.
Apply application allow-listing to prevent unauthorized executables from running.
Mitigation: Ensure Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR) are enabled wit
Ensure Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR) are enabled within the operating system. Memory protection controls can be enabled via Windows Security. Please refer to this article for reference.
Mitigation: Subnet Solutions inc. strongly recommends users update to the latest version. If this is not possibl
Subnet Solutions inc. strongly recommends users update to the latest version. If this is not possible, the following mitigations have been identified:
Patch: Update to CMU Firmware version 13.6.3
Update to CMU Firmware version 13.6.3
Patch: Update to CMU Firmware version 13.5.4
Update to CMU Firmware version 13.5.4
Mitigation: Follow general mitigation factors/workarounds.
Follow general mitigation factors/workarounds.
Patch: Update to CMU Firmware version 12.7.8
Update to CMU Firmware version 12.7.8
Mitigation: Only build and run applications from trusted sources.
Only build and run applications from trusted sources.
Patch: Update to V3.1.5 or later version
Update to V3.1.5 or later version
Mitigation: Only build and run applications from trusted sources.
Only build and run applications from trusted sources.
Patch: Update to V3.1.5 or later version
Update to V3.1.5 or later version
Patch: Update to V3.0 or later version
Update to V3.0 or later version
Patch: Update to V2.4 or later version
Update to V2.4 or later version
Patch: Update to V2.4 or later version
Update to V2.4 or later version
Mitigation: Follow general mitigation factors/workarounds.
Follow general mitigation factors/workarounds.
Mitigation: (CVE-2025-39203) RTU500 series CMU Firmware version 13.4.1 – 13.4.4: Follow General Mitigation Facto
(CVE-2025-39203) RTU500 series CMU Firmware version 13.4.1 – 13.4.4: Follow General Mitigation Factors/Workarounds.
Patch: Update to CMU Firmware version 13.7.7
Update to CMU Firmware version 13.7.7
Patch: Update to CMU Firmware version 13.6.3
Update to CMU Firmware version 13.6.3
Mitigation: (CVE-2025-39205) Hitachi Energy MicroSCADA X SYS600 versions from 10.3 to 10.6: Update to version 10
(CVE-2025-39205) Hitachi Energy MicroSCADA X SYS600 versions from 10.3 to 10.6: Update to version 10.7
Mitigation: Hitachi Energy has identified the following specific workarounds and mitigations users can apply to
Hitachi Energy has identified the following specific workarounds and mitigations users can apply to reduce risk:
Patch: For more information see the associated Hitachi Energy PSIRT security advisory 8DBD000218 Cybersecur
For more information see the associated Hitachi Energy PSIRT security advisory 8DBD000218 Cybersecurity Advisory - Multiple vulnerabilities in Hitachi Energy MicroSCADA Pro/X SYS600 product.
Mitigation: MicroSCADA X SYS600 10.7 is a fixed version for CVE-2025-39205
MicroSCADA X SYS600 10.7 is a fixed version for CVE-2025-39205
Mitigation: The following product versions have been fixed:
The following product versions have been fixed:
Mitigation: For more information see the associated Hitachi Energy PSIRT security advisory 8DBD000220 Multiple V
For more information see the associated Hitachi Energy PSIRT security advisory 8DBD000220 Multiple Vulnerabilities in Hitachi Energy's RTU500 series Product.
Mitigation: Apply general mitigation factors
Apply general mitigation factors
Patch: Upgrade to version 3.5
Upgrade to version 3.5
Patch: Update to V5.0 or later version
Update to V5.0 or later version
Patch: Update to V5.0 or later version
Update to V5.0 or later version

// References