Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2544▼ 345 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.32% | — | ABB Rtu500AI | 29/9/2026 | 29/9/2026 | An improper authorization vulnerability in the end-of-life versions of RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset endpoint. Successful exploitation could cause temporary device unavailability and disruption of its intended operation. | |
| Pendiente de análisis | Crítica (9.1) | 0.74% | — | Hitachienergy Rtu500AI | 29/9/2026 | 29/9/2026 | A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful exploitation could result in unauthorized modification of… | |
| Pendiente de análisis | Crítica (9.1) | 0.58% | — | Hitachienergy Rtu500AI | 29/9/2026 | 29/9/2026 | An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attacker to modify device functionality or compromise the… | |
| Pendiente de análisis | Media (5.9) | 0.27% | — | ABB Rtu500AI | 3/9/2026 | 3/9/2026 | RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry of the enhanced message queue. This can cause a BCI_IEC104 fatal write error, resulting in connection interruption and restart, and ultimately a denial of… | |
| Aplazada | Media (6.9) | 0.25% | — | ABB Rtu500AI | 26/5/2026 | 23/7/2026 | IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially crafted sequence of messages is sent for a certain time, causing Denial of Service impact. Product is only affected if IEC 60870-5-104 functionality in bidirectional mode (BCI) is configured. | |
| Aplazada | Alta (8.7) | 0.33% | — | ABB Rtu500AI | 25/3/2025 | 17/6/2026 | A vulnerability exists in RTU IEC 61850 client and server functionality that could impact the availability if renegotiation of an open IEC61850 TLS connection takes place in specific timing situations, when IEC61850 communication is active. Precondition is that IEC61850 as client or server are configured using TLS on… | |
| Aplazada | Alta (8.7) | 0.40% | — | ABB Rtu500AI | 25/3/2025 | 17/6/2026 | A vulnerability exists in RTU500 IEC 60870-5-104 controlled station functionality and IEC 61850 functionality, that allows an attacker performing a specific attack sequence to restart the affected CMU. This vulnerability only applies, if secure communication using IEC 62351-3 (TLS) is enabled. | |
| Aplazada | Media (6.9) | 0.24% | — | ABB Rtu500AI | 25/3/2025 | 17/6/2026 | A vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and authorized attacker to perform a CMU restart. The vulnerability can be triggered if certificates are updated while in use on active connections. The affected CMU will automatically recover itself if an… | |
| Aplazada | Media (5.9) | 0.34% | — | ABB Rtu500AI | 25/3/2025 | 17/6/2026 | A vulnerability exists in the RTU500 web server component that can cause a denial of service to the RTU500 CMU application if a specially crafted message sequence is executed on a WebSocket connection. An attacker must be properly authenticated and the test mode function of RTU500 must be enabled to exploit this… | |
| Aplazada | Alta (7.2) | 0.66% | — | ABB Rtu500AI | 30/4/2024 | 17/6/2026 | A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if secure update feature was not enabled on all CMUs of a RTU500. If a malicious actor successfully exploits this vulnerability, they could use it to update the RTU500 with unsigned firmware. | |
| Aplazada | Media (6.8) | 0.57% | — | ABB Rtu500AI | 27/3/2024 | 17/6/2026 | A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could enforce diagnostic texts being displayed as empty strings, if an authorized user uploads a specially crafted stb-language file. | |
| Aplazada | Alta (8.2) | 0.45% | — | ABB Rtu500AI | 27/3/2024 | 17/6/2026 | A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could print random memory content in the RTU500 system log, if an authorized user uploads a specially crafted stb-language file. | |
| Modificada | Alta (7.5) | 0.67% | — | Hitachienergy Rtu500 Firmware | 19/12/2023 | 17/6/2026 | Vulnerability exists in SCI IEC 60870-5-104 and HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Specially crafted messages sent to the mentioned components are not validated properly and can result in buffer overflow and as final consequence to a reboot of an RTU500 CMU. | |
| Modificada | Alta (7.5) | 0.32% | — | Hitachienergy Rtu500 Scripting Interface | 19/12/2023 | 17/6/2026 | A vulnerability exists in the component RTU500 Scripting interface. When a client connects to a server using TLS, the server presents a certificate. This certificate links a public key to the identity of the service and is signed by a Certification Authority (CA), allowing the client to validate that the remote… | |
| Modificada | Alta (7.5) | 0.71% | — | Hitachienergy Rtu500 Firmware | 26/7/2023 | 17/6/2026 | A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-3. After session resumption interval is expired an RTU500 initiated update of session parameters… | |
| Modificada | Alta (7.5) | 0.65% | — | Hitachienergy Rtu500 Firmware | 26/7/2023 | 17/6/2026 | A vulnerability exists in the HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be exploited, if the HCI 60870-5-104 is configured with support for IEC 62351-5 and the CMU contains the license feature ‘Advanced security’ which must be ordered separately.… | |
| Modificada | Alta (7.5) | 1.1% | — | Hitachienergy Sys600 FirmwareHitachienergy Rtu500 FirmwareHitachienergy Reb500 FirmwareHitachienergy Pwc600 Firmware+9 | 21/2/2023 | 17/6/2026 | A vulnerability exists in the IEC 61850 communication stack that affects multiple Hitachi Energy products. An attacker could exploit the vulnerability by using a specially crafted message sequence, to force the IEC 61850 MMS-server communication stack, to stop accepting new MMS-client connections. Already… | |
| Modificada | Alta (7.5) | 0.99% | — | ABB Rtu500 FirmwareHitachienergy Rtu500 Firmware | 2/5/2022 | 17/6/2026 | A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is en-abled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500, causing the receiving RTU500 CMU to reboot. The vulnerability is… | |
| Modificada | Alta (7.5) | 0.95% | — | Hitachienergy Rtu500 Firmware | 26/11/2021 | 17/6/2026 | Improper Input Validation vulnerability in the APDU parser in the Bidirectional Communication Interface (BCI) IEC 60870-5-104 function of Hitachi Energy RTU500 series allows an attacker to cause the receiving RTU500 CMU of which the BCI is enabled to reboot when receiving a specially crafted message. By default, BCI… | |
| Modificada | Alta (7.5) | 1.6% | — | Hitachienergy Relion 670 FirmwareHitachienergy Relion 650 FirmwareHitachienergy Relion Sam600-io FirmwareHitachienergy Rtu500 Firmware+5 | 14/6/2021 | 17/6/2026 | Improper Input Validation vulnerability in Hitachi ABB Power Grids Relion 670 Series, Relion 670/650 Series, Relion 670/650/SAM600-IO, Relion 650, REB500, RTU500 Series, FOX615 (TEGO1), MSM, GMS600, PWC600 allows an attacker with access to the IEC 61850 network with knowledge of how to reproduce the attack, as well as… |