CVE-2026-1773: High severity hitachienergy Rtu540 Firmware vulnerability
IEC 60870-5-104 used in RTU500: Potential Denial of Service impact on reception of invalid U-format frame. Product is only affected if IEC 60870-5-104 bi-directional functionality is configured. Enabling secure communication following IEC 62351-3 does not remediate the vulnerability but mitigates the risk of exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1773?
CVE-2026-1773 has a moderate severity level due to the potential for a Denial of Service during invalid U-format frame reception.
How do I fix CVE-2026-1773?
To mitigate CVE-2026-1773, ensure that IEC 60870-5-104 bi-directional functionality is not configured and consider enabling secure communication following IEC 62351-3.
Which products are affected by CVE-2026-1773?
CVE-2026-1773 affects multiple versions of Hitachi Energy RTU540, RTU560, RTU520, RTU530 firmware versions 12.7.1 to 13.8.1.
Can CVE-2026-1773 be exploited remotely?
Yes, CVE-2026-1773 can potentially be exploited remotely if the affected bi-directional functionality is enabled.
What is the impact of CVE-2026-1773?
The primary impact of CVE-2026-1773 is the potential for Denial of Service, affecting the availability of the device's communication functionality.