A vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and authorized attacker to perform a CMU restart. The vulnerability can be triggered if certificates are updated while in use on active connections.
The affected CMU will automatically recover itself if an attacker successfully exploits this vulnerability.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 25 Mar 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and authorized attacker to perform a CMU restart. The vulnerability can be triggered if certificates are updated while in use on active connections. The affected CMU will automatically recover itself if an attacker successfully exploits this vulnerability. | |
Weaknesses | CWE-476 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Hitachi Energy
Published: 2025-03-25T12:30:42.034Z
Updated: 2025-03-25T13:11:58.573Z
Reserved: 2024-11-20T13:16:55.872Z
Link: CVE-2024-11499

Updated: 2025-03-25T13:11:55.406Z

Status : Received
Published: 2025-03-25T13:15:39.890
Modified: 2025-03-25T13:15:39.890
Link: CVE-2024-11499

No data.