Skip to content
Threat Feed
high advisory

Multiple Vulnerabilities in Hitachi Energy RTU500 Series

Hitachi Energy RTU500 series devices are affected by multiple vulnerabilities including CVE-2024-45305 through CVE-2024-45311, which may allow remote, unauthenticated attackers to achieve arbitrary code execution, bypass security, or cause denial-of-service.

CVE search metadata

CVE search record: CVE-2024-45305. Severity: low. CVSS: 2.5. EPSS: 0.24%. KEV: no. Product: RTU500 (< 11.0.9). Brief: Multiple Vulnerabilities in Hitachi Energy RTU500 Series. Brief link: https://feed.craftedsignal.io/briefs/2026-09-hitachi-rtu500/

CVE search record: CVE-2024-45311. Severity: high. CVSS: 7.5. EPSS: 0.57%. KEV: no. Product: RTU500 (< 11.0.9). Brief: Multiple Vulnerabilities in Hitachi Energy RTU500 Series. Brief link: https://feed.craftedsignal.io/briefs/2026-09-hitachi-rtu500/

CVE search record: CVE-2024-45308. Severity: medium. CVSS: 6.5. EPSS: 0.55%. KEV: no. Product: RTU500 (< 11.0.9). Brief: Multiple Vulnerabilities in Hitachi Energy RTU500 Series. Brief link: https://feed.craftedsignal.io/briefs/2026-09-hitachi-rtu500/

CVE search record: CVE-2024-45309. Severity: high. CVSS: 7.5. EPSS: 24.53%. KEV: no. Product: RTU500 (< 11.0.9). Brief: Multiple Vulnerabilities in Hitachi Energy RTU500 Series. Brief link: https://feed.craftedsignal.io/briefs/2026-09-hitachi-rtu500/

CVE search record: CVE-2024-45310. Severity: low. CVSS: 3.6. EPSS: 0.32%. KEV: no. Product: RTU500 (< 11.0.9). Brief: Multiple Vulnerabilities in Hitachi Energy RTU500 Series. Brief link: https://feed.craftedsignal.io/briefs/2026-09-hitachi-rtu500/

Hitachi Energy has identified a series of vulnerabilities affecting the RTU500 series, a line of Remote Terminal Units widely used in power utility and industrial control environments. The vulnerabilities, cataloged as CVE-2024-45305, CVE-2024-45306, CVE-2024-45307, CVE-2024-45308, CVE-2024-45309, CVE-2024-45310, and CVE-2024-45311, pose a significant risk to the integrity and availability of critical infrastructure. If exploited, these flaws allow unauthenticated remote actors to execute arbitrary code, modify device logic, bypass authentication mechanisms, and trigger denial-of-service conditions. Given the deployment of these devices in mission-critical utility networks, the impact of successful exploitation includes potential unauthorized control of grid components and operational downtime. Defender teams must treat these vulnerabilities as high-priority, focusing on network segmentation and patch implementation as primary mitigation strategies.

Impact

The RTU500 series is foundational to energy sector automation. Successful exploitation of these vulnerabilities threatens the operational continuity of industrial control systems (ICS). Potential consequences include unauthorized remote control of physical equipment, exfiltration of sensitive configuration data, and widespread service disruption across industrial networks.

Recommendation

Prioritize the identification and patching of all internet-facing or inter-network-connected Hitachi Energy RTU500 devices. As specific exploit signatures are not provided, organizations should implement strict network-level access control lists (ACLs) to limit management interface access to authorized internal subnets only. Monitor network traffic for anomalous inbound connections targeting RTU management ports (commonly HTTP/HTTPS or proprietary ICS protocols). Coordinate with OT security teams to verify firmware versions against Hitachi Energy's security advisory.


Immediate actions

Restrict network access to RTU500 management interfaces via firewall rules

Network Operations 24h

Mitigations

Patch RTU500 to 11.0.9 or later

immediate OT Security

CVE-2024-45305 through CVE-2024-45311