CVE-2023-4518: Hitachienergy Relion 650 Firmware

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

A vulnerability exists in the input validation of the GOOSE messages where out of range values received and processed by the IED caused a reboot of the device. In order for an attacker to exploit the vulnerability, goose receiving blocks need to be configured.

Affected products

  • Hitachienergy Relion 650 Firmware: from 2.2.4, before 2.2.4.4 (fixed in 2.2.4.4); from 2.2.5, before 2.2.5.6 (fixed in 2.2.5.6); version 2.2.1 only; version 2.2.1.6 only
  • Hitachienergy Relion 670 Firmware: from 2.2.0, before 2.2.2.6 (fixed in 2.2.2.6); from 2.2.3, before 2.2.3.7 (fixed in 2.2.3.7); from 2.2.4, before 2.2.4.4 (fixed in 2.2.4.4); from 2.2.5, before 2.2.5.6 (fixed in 2.2.5.6)
  • Hitachienergy Relion SAM600-Io Firmware: from 2.2.5, before 2.2.5.6 (fixed in 2.2.5.6); version 2.2.1 only; version 2.2.1.6 only

Published 2023-12-01. Last modified 2026-06-17.