CVE-2024-2617Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if secure update feature was not enabled on all CMUs of a RTU500. If a malicious actor successfully exploits this vulnerability, they could use it to update the RTU500 with unsigned firmware.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-358

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-14: 1Technical Details · 2026-02-14: 102-14
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Ravi Nayyar@ravirockks
    Disclosure

    '... [Hitachi Energy] RTU560 [RTUs] .... default credentials ... a security feature meant to prevent malicious firmware updates had not been enabled, but even if it had been enabled the devices were affected by CVE-2024-2617, a known flaw allowing unsigned firmware updates.

    Post summary

    The text discloses that Hitachi Energy RTU560 devices are impacted by CVE‑2024‑2617, a flaw permitting unsigned firmware updates, without mentioning any PoC, exploit, or patch.

    1000057
    1.2K followersView on X

Explore more