« Volver al listado

CVE-2024-2617

Estado: AplazadaAlta (7.2)—

A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update,

if secure update feature was not enabled on all CMUs of a RTU500. If a malicious actor successfully exploits this vulnerability, they could use it to update the RTU500 with unsigned firmware.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-2617",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-2617",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-04-30T16:11:48.392692Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cybersecurity@hitachienergy.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "cybersecurity@hitachienergy.com",
      "affectedData": [
        {
          "vendor": "Hitachi Energy",
          "product": "RTU500 series CMU firmware",
          "versions": [
            {
              "status": "affected",
              "version": "13.2.1",
              "versionType": "custom",
              "lessThanOrEqual": "13.2.7"
            },
            {
              "status": "affected",
              "version": "13.4.1",
              "versionType": "custom",
              "lessThanOrEqual": "13.4.4"
            },
            {
              "status": "affected",
              "version": "13.5.1",
              "versionType": "custom",
              "lessThanOrEqual": "13.5.3"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:hitachienergy:rtu500_firmware:13.2.1.0:*:*:*:*:*:*:*"
          ],
          "vendor": "hitachienergy",
          "product": "rtu500_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "13.2.1.0",
              "versionType": "custom",
              "lessThanOrEqual": "13.2.7.0"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:hitachienergy:rtu500_firmware:13.4.1.0:*:*:*:*:*:*:*"
          ],
          "vendor": "hitachienergy",
          "product": "rtu500_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "13.4.1.0",
              "versionType": "custom",
              "lessThanOrEqual": "13.4.4.0"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:hitachienergy:rtu500_firmware:13.5.1.0:*:*:*:*:*:*:*"
          ],
          "vendor": "hitachienergy",
          "product": "rtu500_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "13.5.1.0",
              "versionType": "custom",
              "lessThanOrEqual": "13.5.3.0"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-04-30T13:15:47.200",
  "references": [
    {
      "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000199&languageCode=en&Preview=true",
      "source": "cybersecurity@hitachienergy.com"
    },
    {
      "url": "https://publisher.hitachienergy.com/preview?DocumentId=8DBD000199&languageCode=en&Preview=true",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-358"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, \n\nif secure update feature was not enabled on all\nCMUs of a RTU500. If a\nmalicious actor successfully exploits this vulnerability, they\ncould use it to update the RTU500 with unsigned firmware."
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad en el RTU500 que permite a los usuarios autenticados y autorizados omitir la actualización segura. Si un actor malintencionado aprovecha con éxito esta vulnerabilidad, podría usarla para actualizar el RTU500 con firmware sin firmar."
    }
  ],
  "lastModified": "2026-06-17T07:24:54.053",
  "sourceIdentifier": "cybersecurity@hitachienergy.com"
}