CVE-2026-8479: Hitachi Energy RTU500 Series Cmu Firmware
Medium severity, CVSS 6.9. EPSS: 0.2% chance of exploitation in the next 30 days.
IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially crafted sequence of messages is sent for a certain time, causing Denial of Service impact. Product is only affected if IEC 60870-5-104 functionality in bidirectional mode (BCI) is configured.
Affected products
- Hitachi Energy RTU500 Series Cmu Firmware: from 12.7.1, up to and including 12.7.7; from 13.5.1, up to and including 13.5.4; from 13.6.1, up to and including 13.6.3; from 13.7.1, up to and including 13.7.8; version 13.8.1 only
Published 2026-05-26. Last modified 2026-07-23.