We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-1445



Description

A vulnerability exists in RTU IEC 61850 client and server functionality that could impact the availability if renegotiation of an open IEC61850 TLS connection takes place in specific timing situations, when IEC61850 communication is active. Precondition is that IEC61850 as client or server are configured using TLS on RTU500 device. It affects the CMU the IEC61850 stack is configured on.

Reserved 2025-02-18 | Published 2025-03-25 | Updated 2025-03-25 | Assigner Hitachi Energy


HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/R:A

HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-820: Missing Synchronization

Product status

Default status
unaffected

13.7.1
affected

13.7.6
unaffected

References

publisher.hitachienergy.com/...&languageCode=en&Preview=true

cve.org (CVE-2025-1445)

nvd.nist.gov (CVE-2025-1445)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-1445

Support options

Helpdesk Chat, Email, Knowledgebase