Impact
A directory traversal flaw (CWE-23) in the firmware of Hitachi Energy RTU500 series devices lets an unauthenticated attacker write arbitrary files to the system. By overwriting configuration or executable files, an attacker could modify device data or disrupt operation, disabling critical functions.
Affected Systems
The vulnerability affects Hitachi Energy RTU500 series RTU firmware that has reached end‑of‑life. No specific version numbers are provided; any device running the affected firmware is potentially compromised.
Risk and Exploitability
The CVSS score of 9.1 indicates high severity, and the EPSS score of 0.01157 suggests that exploitation is plausible, although not extremely common. The vulnerability is not listed in the CISA KEV catalog, but its impact and ease of exploitation make it a significant risk. An attacker would likely exploit the weakness by sending a crafted upload request that triggers the directory traversal, uploading a file that implements malicious logic or alters configuration. Because no authentication is required, anyone with network access to the device could carry out the attack.
OpenCVE Enrichment