CVE-2025-1445
A vulnerability exists in RTU IEC 61850 client and server functionality that could impact the availability if renegotiation of an open IEC61850 TLS connection takes place in specific timing situations, when IEC61850 communication is active. Precondition is that IEC61850 as client or server are configured using TLS on RTU500 device. It affects the CMU the IEC61850 stack is configured on.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/R:A
- EPSS probability
- 0.32%
- CWE
- CWE-820
- Published
- 2025-03-25
- Last modified
- 2026-03-13
Affected products
- Hitachi Energy RTU500
- Hitachi Energy RTU500
Weakness type
Related vulnerabilities
- CVE-2026-70637 — LightFTP 2.4 Data Race Condition via ABOR Command in ftpserv.c
- CVE-2026-57029 — Junos OS Evolved: QFX Series: When sFlow collector reachability changes evo-pfemand process can crash
- CVE-2026-44318 — free5GC: BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes the BSF process via concurrent map read/write on Subscriptions
- CVE-2026-22163 — GPU DDK - Unsafe writing of MMU PT entries on systems with 32-bit host CPU
- CVE-2022-50238 — The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online...
- CVE-2025-49751 — Windows Hyper-V Denial of Service Vulnerability
- CVE-2025-47999 — Windows Hyper-V Denial of Service Vulnerability
- CVE-2025-47154 — LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list...