Impact
An improper authorization flaw in the web application of Hitachi Energy’s RTU500 series allows an authenticated user to call a reset endpoint that forces the device to reboot. The attacker simply needs valid credentials and can cause the RTU500 to become temporarily unavailable. This disruption can halt the device’s intended operation, presenting a denial‑of‑service risk for any critical process relying on the RTU500.
Affected Systems
The vulnerability affects end‑of‑life versions of the RTU500 series Customer Management Unit firmware supplied by Hitachi Energy. No specific firmware revisions are listed, so any unreleased or legacy RTU500 firmware in the field may be susceptible if it has not been upgraded beyond the end‑of‑life threshold.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1 % suggests a low probability of exploitation. The flaw is not designated in CISA’s KEV catalog, further implying limited real‑world use. However, should an attacker gain authenticated access, they can force a reboot and disrupt services. The primary attack vector is the exposed web interface and requires legitimate credentials as the only prerequisite.
OpenCVE Enrichment