← back
CVE-2024-11499

CVE-2024-11499

CVSS 6.9 MEDIUMEPSS 0.2%CWE-476
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.9EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
25 Mar 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and authorized attacker to perform a CMU restart. The vulnerability can be triggered if certificates are updated while in use on active connections. The affected CMU will automatically recover itself if an attacker successfully exploits this vulnerability.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/R:A
Affected products
Hitachi Energy · RTU500

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →