Hitachi Energy RTU500 series
Buffer overflow vulnerability in Hitachi Energy RTU500 series CMU (communication module) firmware versions 13.3.1 and 13.3.2. The vulnerability exists in the HCI IEC 60870-5-104 protocol implementation. A remote attacker can send a malicious packet to the HCI interface, causing a buffer overflow that triggers a device reboot, temporarily disrupting SCADA communications. The vulnerability affects only devices with HCI IEC 60870-5-104 and IEC 62351-5 (or IEC 62351-3) configured and enabled. By default, these features are disabled.
- Network reachability to the RTU500 device on the HCI IEC 60870-5-104 port (typically 2404/TCP for IEC 60870-5-104)
- HCI IEC 60870-5-104 function must be enabled on the device (disabled by default)
- No authentication required
Patching may require device reboot — plan for process interruption
/api/v1/advisories/0a74ac78-32f4-4c57-ac9f-316255b74579Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.