CVE-2024-12169: Hitachi Energy RTU500

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability exists in RTU500 IEC 60870-5-104 controlled station functionality and IEC 61850 functionality, that allows an attacker performing a specific attack sequence to restart the affected CMU. This vulnerability only applies, if secure communication using IEC 62351-3 (TLS) is enabled.

Affected products

  • Hitachi Energy RTU500: from 13.4.1, up to and including 13.4.4; from 13.5.1, up to and including 13.5.3; version 13.6.1 only; from 13.7.1, up to and including 13.7.4

Published 2025-03-25. Last modified 2026-06-17.