CVE-2026-17539: Null Pointer Dereference
RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry of the enhanced message queue. This can cause a BCIIEC104 fatal write error, resulting in connection interruption and restart, and ultimately a denial of service for bidirectional IEC 60870-5-104 communication.
Affected Software
Event History
Frequently Asked Questions
What traffic pattern is required to trigger the denial of service?
The issue occurs under high-load conditions, with GI requests sent at short intervals identified as an example. Exploitation requires network access but has high attack complexity.
What is the operational impact if the vulnerability is triggered?
A NULL pointer dereference in the last enhanced message queue entry can cause a BCI_IEC104 fatal write error. This interrupts and restarts the connection, denying bidirectional IEC 60870-5-104 communication.