Where
AND
-Infinity
0
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A vulnerability exists in the IEC 61850 communication stack that affects multiple Hitachi Energy products.

An attacker could exploit the vulnerability by using a specially crafted message sequence, to force the IEC 61850 MMS-server communication stack, to stop accepting new MMS-client connections.

Already existing/established client-server connections are not affected.

List of affected CPEs:

cpe:2.3:o:hitachienergy:fox61xtego1:r15b08::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r2a163::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r2a16::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r1e01::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r1d02::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r1c07::::::: cpe:2.3:o:hitachienergy:fox61xtego1:r1b02::::::: cpe:2.3:a:hitachienergy:gms600:1.3.0::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.1.::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.5.::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.6.0::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.6.0.1::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.7.0::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.7.2::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:1.8.0::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:2.0.::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:2.1.0.4::::::: cpe:2.3:a:hitachienergy:itt600saexplorer:2.1.0.5::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.2::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.2.1::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.3::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.3.1::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.4::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.4.1::::::: cpe:2.3:a:hitachienergy:mms:2.2.3::::::: cpe:2.3:a:hitachienergy:pwc600:1.0::::::: cpe:2.3:a:hitachienergy:pwc600:1.1::::::: cpe:2.3:a:hitachienergy:pwc600:1.2::::::: cpe:2.3:o:hitachienergy:reb500:7:::::::: cpe:2.3:o:hitachienergy:reb500:8::::::: cpe:2.3:o:hitachienergy:relion670:1.2.::::::: cpe:2.3:o:hitachienergy:relion670:2.0.::::::: cpe:2.3:o:hitachienergy:relion650:1.1.::::::: cpe:2.3:o:hitachienergy:relion650:1.3.::::::: cpe:2.3:o:hitachienergy:relion650:2.1.::::::: cpe:2.3:o:hitachienergy:relion670:2.1.::::::: cpe:2.3:o:hitachienergy:relionSAM600-IO:2.2.1::::::: cpe:2.3:o:hitachienergy:relionSAM600-IO:2.2.5::::::: cpe:2.3:o:hitachienergy:relion670:2.2.::::::: cpe:2.3:o:hitachienergy:relion650:2.2.::::::: cpe:2.3:o:hitachienergy:rtu500cmu:12..::::::: cpe:2.3:a:hitachienergy:rtu500cmu:13..::::::: cpe:2.3:a:hitachienergy:txperthubcoretec4:2.::::::: cpe:2.3:a:hitachienergy:txperthubcoretec4:3.0::::::: cpe:2.3:a:hitachienergy:txperthubcoretec5:3.0:::::::

1 / 2
Source: MITRE

Remedy

Upgrade the system once remediated version is available.
First published (updated )
Severity
7.5
EPSS
0.05%
Buffer Overflow
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability exists in SCI IEC 60870-5-104 and HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Specially crafted messages sent to the mentioned components are not validated properly and can result in buffer overflow and as final consequence to a reboot of an RTU500 CMU.

First published (updated )
Severity
10
Input Validation
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is en-abled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500, causing the receiving RTU500 CMU to reboot. The vulnerability is caused by the validation error in the length information carried in MBAP header in the HCI Modbus TCP function.

1 / 2
Source: MITRE

Remedy

Remediation available, see the advisory for details.
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203