CVE-2024-2617
Published: Apr 30, 2024
Modified: Mar 4, 2026
CVSS v3.1
7.2
Description
A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if secure update feature was not enabled on all CMUs of a RTU500. If a malicious actor successfully exploits this vulnerability, they could use it to update the RTU500 with unsigned firmware.
| Vendor | Product | Versions |
|---|---|---|
Hitachi Energy | RTU500 series CMU firmware | affected 13.2.1 - <= 13.2.7affected 13.4.1 - <= 13.4.4affected 13.5.1 - <= 13.5.3 |
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now