CVE-2026-17539
Received Received - Intake

NULL Pointer Dereference in RTU500 IEC 60870-5-104 Communication

Vulnerability report for CVE-2026-17539, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: Hitachi Energy

Description

RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry of the enhanced message queue. This can cause a BCI_IEC104 fatal write error, resulting in connection interruption and restart, and ultimately a denial of service for bidirectional IEC 60870-5-104 communication.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-03
AI Q&A
2026-09-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hitachi_energy rtu500 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

RTU500 has a vulnerability where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry of the enhanced message queue. This leads to a BCI_IEC104 fatal write error, causing connection interruption and restart, resulting in a denial of service for bidirectional IEC 60870-5-104 communication.

Detection Guidance

Monitor for BCI_IEC104 fatal write errors or connection interruptions in RTU500 devices. Check logs for NULL pointer dereference events during high-load scenarios like frequent GI requests. No specific commands are provided in the context.

Impact Analysis

This vulnerability can cause a denial of service for IEC 60870-5-104 communication, disrupting bidirectional control and monitoring. It may lead to connection interruptions and restarts, affecting real-time data exchange and operational continuity.

Mitigation Strategies

Limit the frequency of GI requests to reduce load on the RTU500 device. Implement rate limiting or throttling for IEC 60870-5-104 communication. Ensure redundancy or failover mechanisms to maintain bidirectional communication during disruptions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17539. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart