A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update,
if secure update feature was not enabled on all
CMUs of a RTU500. If a
malicious actor successfully exploits this vulnerability, they
could use it to update the RTU500 with unsigned firmware.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update. If a malicious actor successfully exploits this vulnerability, they could use it to update the RTU500 with unsigned firmware. | A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if secure update feature was not enabled on all CMUs of a RTU500. If a malicious actor successfully exploits this vulnerability, they could use it to update the RTU500 with unsigned firmware. |
| First Time appeared |
Hitachienergy
Hitachienergy rtu500 Firmware |
|
| CPEs | cpe:2.3:o:hitachienergy:rtu500_firmware:13.2.1.0:*:*:*:*:*:*:* cpe:2.3:o:hitachienergy:rtu500_firmware:13.4.1.0:*:*:*:*:*:*:* cpe:2.3:o:hitachienergy:rtu500_firmware:13.5.1.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Hitachienergy
Hitachienergy rtu500 Firmware |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Hitachi Energy
Published:
Updated: 2026-03-04T12:02:50.897Z
Reserved: 2024-03-18T17:44:43.352Z
Link: CVE-2024-2617
Updated: 2024-08-01T19:18:48.011Z
Status : Awaiting Analysis
Published: 2024-04-30T13:15:47.200
Modified: 2026-03-04T12:16:01.437
Link: CVE-2024-2617
No data.
OpenCVE Enrichment
No data.