CVE-2024-8176
CVSS 7.5 HIGH: a stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. EPSS 1% (69th percentile).
Vulnerabilities · 196 days ago
An unprivileged user can read user-management information. Malformed IEC 60870-5-104 U-frames can disrupt RTU operation, and authenticated REB500 roles can access or alter unauthorized directories; devices are deployed in the energy sector and other critical infrastructure.
CVSS 7.5 HIGH: a stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. EPSS 1% (69th percentile).
CVSS 7.5 HIGH: libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that… EPSS 1% (68th percentile).
CVSS 7.5 HIGH: iEC 60870-5-104: Potential Denial of Service impact on reception of invalid U-format frame. Product is only affected if IEC 60870-5-104 bi-directional functionality is configured. EPSS 0.4% (33rd percentile).
CVSS 5.3 MEDIUM: rTU500 web interface: An unprivileged user can read user management information. EPSS 0.3% (17th percentile).
1 source covering this story
Hitachi Energy Relion REB500 Product | CISA
Hitachi Energy Relion REB500 Product Summary Hitachi Energy is aware of vulnerabilities that affect the Relion REB500 product versions listed in this document.
Hitachi Energy RTU500 Product | CISA
Hitachi Energy RTU500 Product Summary Hitachi Energy is aware of vulnerabilities that affect RTU500 product versions listed in this document.
Part of the PlainSec briefing for 2026-03-04