CVE-2026-2460: High severity hitachienergy Reb500 Firmware vulnerability
A vulnerability exists in REB500 for an authenticated user with low-level privileges to access and alter the content of directories by using the DAC protocol that the user is not authorized to do so.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2460?
CVE-2026-2460 is considered to have a medium severity due to potential unauthorized access and modification of directory content by low-privilege authenticated users.
How does CVE-2026-2460 affect user permissions in REB500?
CVE-2026-2460 allows authenticated users with low-level privileges to alter directories they should not have access to, potentially leading to data integrity issues.
What versions of REB500 are affected by CVE-2026-2460?
CVE-2026-2460 affects all versions of Hitachi Energy's REB500 firmware up to version 8.3.3.1.
Is there a patch available for CVE-2026-2460?
As of now, there is no specific patch released for CVE-2026-2460, and users should consult Hitachi Energy’s communications for updates.
What mitigation strategies can be employed for CVE-2026-2460?
Mitigation for CVE-2026-2460 involves restricting authenticated user access based on role and closely monitoring directory activities.