CVE-2026-8479: Null Pointer Dereference
IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially crafted sequence of messages is sent for a certain time, causing Denial of Service impact. Product is only affected if IEC 60870-5-104 functionality in bidirectional mode (BCI) is configured.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8479?
The severity of CVE-2026-8479 is medium with a CVSS score of 6.9.
What type of vulnerability is CVE-2026-8479?
CVE-2026-8479 is a null pointer dereference vulnerability leading to a Denial of Service condition.
How can CVE-2026-8479 be exploited?
CVE-2026-8479 can be exploited by sending a specially crafted sequence of messages for a certain duration.
Which product is affected by CVE-2026-8479?
RTU500 is the product affected by CVE-2026-8479 when using IEC 60870-5-104 functionality in bidirectional mode.
How do I remediate CVE-2026-8479?
Mitigation for CVE-2026-8479 involves disabling the IEC 60870-5-104 functionality in bidirectional mode if not needed.