Home

Description

A vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and authorized attacker to perform a CMU restart. The vulnerability can be triggered if certificates are updated while in use on active connections. The affected CMU will automatically recover itself if an attacker successfully exploits this vulnerability.

PUBLISHED Reserved 2024-11-20 | Published 2025-03-25 | Updated 2025-03-25 | Assigner Hitachi Energy




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/R:A

MEDIUM: 4.9CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-476 NULL Pointer Dereference

Product status

Default status
unaffected

13.4.1 (custom)
affected

13.5.1 (custom)
affected

13.5.3 (custom)
affected

13.6.1 (custom)
affected

13.7.1 (custom)
affected

13.5.4 (custom)
unaffected

13.6.2 (custom)
unaffected

13.7.6 (custom)
unaffected

References

publisher.hitachienergy.com/...&languageCode=en&Preview=true

cve.org (CVE-2024-11499)

nvd.nist.gov (CVE-2024-11499)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.