Description
RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry of the enhanced message queue. This can cause a BCI_IEC104 fatal write error, resulting in connection interruption and restart, and ultimately a denial of service for bidirectional IEC 60870-5-104 communication.
Published: 2026-09-03
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Hitachi Energy RTU500 firmware is a null pointer dereference triggered when the enhanced message queue is overloaded by rapid GI requests. This flaw leads to a fatal write error in the BCI_IEC104 component, causing the IEC 60870‑5‑104 connection to drop, requiring a restart, and ultimately denying bidirectional communication over the protocol.

Affected Systems

Affected devices are Hitachi Energy RTU500 series CMU firmware. No specific firmware version ranges are listed; any system running current RTU500 firmware is potentially impacted.

Risk and Exploitability

With a CVSS score of 5.9 the vulnerability rates as medium severity. The EPSS score is not available, and it is not listed in the CISA KEV catalogue, indicating no known large‑scale exploitation. The likely attack vector is network‑based, where an adversary could generate a sustained stream of IEC 60870‑5‑104 GI requests to trigger the crash. Because the flaw has no privilege requirements, any remote host with network access to the target can exploit it, resulting in service disruption.

Generated by OpenCVE AI on September 3, 2026 at 09:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor's official patch once released.
  • Limit the frequency of GI requests sent to the RTU to prevent queue saturation.
  • Monitor IEC 60870‑5‑104 traffic for abnormal load and log repeated GI requests.
  • If possible, isolate or disconnect the device from the network during periods of heavy load or when a patch is not available.
  • Implement rate limiting or traffic shaping on upstream network devices to protect the RTU from abrupt GI bursts.

Generated by OpenCVE AI on September 3, 2026 at 09:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Hitachienergy
Hitachienergy rtu500 Firmware
Vendors & Products Hitachienergy
Hitachienergy rtu500 Firmware

Thu, 03 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via NULL Pointer Dereference in Hitachi Energy RTU500 IEC 60870-5-104 Communication

Thu, 03 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Description RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry of the enhanced message queue. This can cause a BCI_IEC104 fatal write error, resulting in connection interruption and restart, and ultimately a denial of service for bidirectional IEC 60870-5-104 communication.
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Hitachienergy Rtu500 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Hitachi Energy

Published:

Updated: 2026-09-03T12:48:06.779Z

Reserved: 2026-07-27T09:46:09.631Z

Link: CVE-2026-17539

cve-icon Vulnrichment

Updated: 2026-09-03T12:48:03.247Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-03T13:04:35.693

Modified: 2026-09-03T16:43:15.293

Link: CVE-2026-17539

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:30:05Z

Weaknesses