CVE-2024-2617
EUVD-2024-2756630.04.2024, 13:15
A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if secure update feature was not enabled on all CMUs of a RTU500. If a malicious actor successfully exploits this vulnerability, they could use it to update the RTU500 with unsigned firmware.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| hitachienergy | rtu500_firmware | 13.2.1.0 ≤ 𝑥 ≤ 13.2.7.0 | ADP |
| hitachienergy | rtu500_firmware | 13.4.1.0 ≤ 𝑥 ≤ 13.4.4.0 | ADP |
| hitachienergy | rtu500_firmware | 13.5.1.0 ≤ 𝑥 ≤ 13.5.3.0 | ADP |
Common Weakness Enumeration