Hitachi Energy REB500
What happened
These vulnerabilities can be exploited to carry out Denial of Service (DoS) attack on the product. View CSAF Summary Hitachi Energy is aware of open-source software vulnerabilities that affect REB500 product versions listed in this document.
Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. An authenticated malicious user with local access could use a crafted IEC 61850 message to exploit the vulnerability in the libexpat library.
Notice The information in this document is subject to change without notice and should not be construed as a commitment by Hitachi Energy. Hitachi Energy provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document.
Key facts
- Hitachi Energy โ provides: no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document
Sources & evidence
- CISA Advisories Primary / official
Hitachi Energy REB500 โ
https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-05