Home

Description

IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially crafted sequence of messages is sent for a certain time, causing Denial of Service impact. Product is only affected if IEC 60870-5-104 functionality in bidirectional mode (BCI) is configured.

PUBLISHED Reserved 2026-05-13 | Published 2026-05-26 | Updated 2026-05-26 | Assigner Hitachi Energy




MEDIUM: 6.9CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-476 NULL pointer dereference

Product status

Default status
unaffected

12.7.1 (custom)
affected

13.5.1 (custom)
affected

13.6.1 (custom)
affected

13.7.1 (custom)
affected

13.8.1 (custom)
affected

References

publisher.hitachienergy.com/...DocumentPartId=&Action=Launch

cve.org (CVE-2026-8479)

nvd.nist.gov (CVE-2026-8479)

Download JSON