Hitachi Energy RTU500
What happened
View CSAF Summary Hitachi Energy is publishing this cybersecurity advisory in response to the security findings reported by Dragos affecting end-of-life RTU500 CMU firmware version 9.x. Over successive RTU500 releases, Hitachi Energy has continuously enhanced the security of the product through the introduction of additional security features, protocol hardening, stronger authentication and access controls, encrypted communications, and other security-by-design improvements.
The reported findings are associated with legacy RTU500 firmware versions that were developed according to the cybersecurity requirements, threat landscape, and industry practices that existed at the time of their release. As cybersecurity threats and security expectations have evolved, these end-of-life versions no longer incorporate many of the security controls and hardening measures that are standard in modern industrial control systems.
Sources & evidence
- CISA Advisories Primary / official
Hitachi Energy RTU500 ↗
https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-06