Where
-Infinity
0
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A vulnerability exists in the IEC 61850 communication stack that affects multiple Hitachi Energy products.

An attacker could exploit the vulnerability by using a specially crafted message sequence, to force the IEC 61850 MMS-server communication stack, to stop accepting new MMS-client connections.

Already existing/established client-server connections are not affected.

List of affected CPEs:

cpe:2.3:o:hitachienergy:fox61xtego1:r15b08::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r2a163::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r2a16::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r1e01::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r1d02::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r1c07::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r1b02::::::: cpe:2.3:a:hitachienergy:gms600:1.3.0::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.1.::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.5.::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.6.0::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.6.0.1::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.7.0::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.7.2::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.8.0::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:2.0.::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:2.1.0.4::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:2.1.0.5::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.2::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.2.1::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.3::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.3.1::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.4::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.4.1::::::: cpe:2.3:a:hitachienergy:mms:2.2.3::::::: cpe:2.3:a:hitachienergy:pwc600:1.0::::::: cpe:2.3:a:hitachienergy:pwc600:1.1::::::: cpe:2.3:a:hitachienergy:pwc600:1.2::::::: cpe:2.3:o:hitachienergy:reb500:7:::::::: cpe:2.3:o:hitachienergy:reb500:8::::::: cpe:2.3:o:hitachienergy:relion670:1.2.::::::: cpe:2.3:o:hitachienergy:relion670:2.0.::::::: cpe:2.3:o:hitachienergy:relion650:1.1.::::::: cpe:2.3:o:hitachienergy:relion650:1.3.::::::: cpe:2.3:o:hitachienergy:relion650:2.1.::::::: cpe:2.3:o:hitachienergy:relion670:2.1.::::::: cpe:2.3:o:hitachienergy:relionSAM600-IO:2.2.1::::::: cpe:2.3:o:hitachienergy:relionSAM600-IO:2.2.5::::::: cpe:2.3:o:hitachienergy:relion670:2.2.::::::: cpe:2.3:o:hitachienergy:relion650:2.2.::::::: cpe:2.3:o:hitachienergy:rtu500cmu:12..::::::: cpe:2.3:a:hitachienergy:rtu500cmu:13..::::::: cpe:2.3:a:hitachienergy:txperthubcoretec4:2.::::::: cpe:2.3:a:hitachienergy:txperthubcoretec4:3.0::::::: cpe:2.3:a:hitachienergy:txperthubcoretec5:3.0:::::::

1 / 2
Source: MITRE

Remedy

Upgrade the system once remediated version is available.
First published (updated )
Severity
7.5
Input Validation
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A vulnerability exists in the HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-5 and the CMU contains the license feature ‘Advanced security’ which must be ordered separately. If these preconditions are fulfilled, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500, causing the targeted RTU500 CMU to reboot. The vulnerability is caused by a missing input data validation which eventually if exploited causes an internal buffer to overflow in the HCI IEC 60870-5-104 function.

Remedy

Update to CMU Firmware versions 13.3.3 or 13.4.1.
First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-3. After session resumption interval is expired an RTU500 initiated update of session parameters causes an unexpected restart due to a stack overflow.

Remedy

Update to CMU Firmware versions 13.3.3 or 13.4.1.
First published (updated )
Severity
7.5
EPSS
0.05%
Buffer Overflow
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability exists in SCI IEC 60870-5-104 and HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Specially crafted messages sent to the mentioned components are not validated properly and can result in buffer overflow and as final consequence to a reboot of an RTU500 CMU.

First published (updated )
Severity
10
Input Validation
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is en-abled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500, causing the receiving RTU500 CMU to reboot. The vulnerability is caused by the validation error in the length information carried in MBAP header in the HCI Modbus TCP function.

1 / 2
Source: MITRE

Remedy

Remediation available, see the advisory for details.
First published (updated )
Severity
7.5
Input Validation
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Improper Input Validation vulnerability in Hitachi ABB Power Grids Relion 670 Series, Relion 670/650 Series, Relion 670/650/SAM600-IO, Relion 650, REB500, RTU500 Series, FOX615 (TEGO1), MSM, GMS600, PWC600 allows an attacker with access to the IEC 61850 network with knowledge of how to reproduce the attack, as well as the IP addresses of the different IEC 61850 access points (of IEDs/products), to force the device to reboot, which renders the device inoperable for approximately 60 seconds. This vulnerability affects only products with IEC 61850 interfaces. This issue affects: Hitachi ABB Power Grids Relion 670 Series 1.1; 1.2.3 versions prior to 1.2.3.20; 2.0 versions prior to 2.0.0.13; 2.1; 2.2.2 versions prior to 2.2.2.3; 2.2.3 versions prior to 2.2.3.2. Hitachi ABB Power Grids Relion 670/650 Series 2.2.0 versions prior to 2.2.0.13. Hitachi ABB Power Grids Relion 670/650/SAM600-IO 2.2.1 versions prior to 2.2.1.6. Hitachi ABB Power Grids Relion 650 1.1; 1.2; 1.3 versions prior to 1.3.0.7. Hitachi ABB Power Grids REB500 7.3; 7.4; 7.5; 7.6; 8.2; 8.3. Hitachi ABB Power Grids RTU500 Series 7.x version 7.x and prior versions; 8.x version 8.x and prior versions; 9.x version 9.x and prior versions; 10.x version 10.x and prior versions; 11.x version 11.x and prior versions; 12.x version 12.x and prior versions. Hitachi ABB Power Grids FOX615 (TEGO1) R1D02 version R1D02 and prior versions. Hitachi ABB Power Grids MSM 2.1.0 versions prior to 2.1.0. Hitachi ABB Power Grids GMS600 1.3.0 version 1.3.0 and prior versions. Hitachi ABB Power Grids PWC600 1.0 versions prior to 1.0.1.4; 1.1 versions prior to 1.1.0.1.

Remedy

Refer to the cybersecurity advisories at https://www.hitachiabb-powergrids.com/offering/solutions/cybersecurity/alerts-and-notifications
First published (updated )
Severity
7.5
Input Validation
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Improper Input Validation vulnerability in the APDU parser in the Bidirectional Communication Interface (BCI) IEC 60870-5-104 function of Hitachi Energy RTU500 series allows an attacker to cause the receiving RTU500 CMU of which the BCI is enabled to reboot when receiving a specially crafted message. By default, BCI IEC 60870-5-104 function is disabled (not configured). This issue affects: Hitachi Energy RTU500 series CMU Firmware version 12.0. (all versions); CMU Firmware version 12.2. (all versions); CMU Firmware version 12.4. (all versions).

Remedy

- Disable BCI IEC 60870-5-104 function by configuration if it is not used. - Update to RTU500 series CMU Firmware version 12.6.5.0 or later (e.g., RTU500 CMU Firmware version 12.7.* or CMU Firmware version 13.2.* or later).
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203