CVE-2024-2617: Hitachi Energy RTU500 Series Cmu Firmware
High severity, CVSS 7.2. EPSS: 0.7% chance of exploitation in the next 30 days.
A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if secure update feature was not enabled on all CMUs of a RTU500. If a malicious actor successfully exploits this vulnerability, they could use it to update the RTU500 with unsigned firmware.
Affected products
- Hitachi Energy RTU500 Series Cmu Firmware: from 13.2.1, up to and including 13.2.7; from 13.4.1, up to and including 13.4.4; from 13.5.1, up to and including 13.5.3
- Hitachienergy RTU500 Firmware: from 13.2.1.0, up to and including 13.2.7.0; from 13.4.1.0, up to and including 13.4.4.0; from 13.5.1.0, up to and including 13.5.3.0
Published 2024-04-30. Last modified 2026-06-17.