RTU500 存在一个漏洞:在高负载场景下(例如以较短的时间间隔发送 GI 请求),可能导致增强型消息队列最后一个条目发生空指针解引用。这会引发 BCI_IEC104 的致命写错误,导致连接中断并重启,最终造成 IEC 60870-5-104 双向通信的服务中断。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Hitachi Energy | RTU500 series CMU firmware | 12.7.1≤ 12.7.7 |
affected |
13.5.1≤ 13.5.4 |
affected | ||
13.6.1≤ 13.6.3 |
affected | ||
13.7.1≤ 13.7.8 |
affected | ||
13.8.1≤ 13.8.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Hitachi Energy | RTU500 series CMU firmware | 12.7.1 ~ 12.7.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-9854 | 8.5 HIGH | SYS600 RBAC权限提升至Windows管理员漏洞 |
| CVE-2026-9853 | 8.5 HIGH | SYS600 认证缺失致对象越权读写漏洞 |
| CVE-2026-9852 | 4.6 MEDIUM | SYS600 CSV注入漏洞 |
No comments yet