PatchSiren cyber security CVE debrief
CVE-2024-11499 Hitachi Energy CVE debrief
CVE-2024-11499 is a medium-severity availability issue in Hitachi Energy RTU500 Series CMU Firmware. According to the CISA CSAF advisory, an authenticated and authorized attacker can trigger a CMU restart when certificates are updated while they are in use on active connections. The CMU is described as automatically recovering after a successful exploit, but the restart can still interrupt service. The advisory was published on 2025-03-25 and later revised to add fixed versions for some branches.
- Vendor
- Hitachi Energy
- Product
- CMU Firmware
- CVSS
- MEDIUM 4.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-03-25
- Original CVE updated
- 2025-09-09
- Advisory published
- 2025-03-25
- Advisory updated
- 2025-09-09
Who should care
Operators and maintainers of Hitachi Energy RTU500 environments, especially teams that manage IEC 60870-5-104 controlled station functionality, certificate lifecycle operations, and availability-sensitive OT/ICS deployments.
Technical summary
The advisory describes a network-reachable attack path with high privileges required (CVSS 3.1: AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). The triggering condition is certificate replacement while those certificates are actively used on live connections, which can cause the CMU to restart. The affected firmware ranges are 13.4.1–13.4.4, 13.5.1–13.5.3, 13.6.1, and 13.7.1–13.7.4. Fixed versions listed in the advisory revisions are 13.5.4, 13.6.3, and 13.7.7; for 13.4.1–13.4.4, the supplied remediation guidance points to general mitigation factors/workarounds and upgrading when a remediated version is available.
Defensive priority
Medium priority. Prioritize if the CMU is externally reachable, certificate updates are routine, or a restart would affect critical control communications; otherwise schedule remediation into the next maintenance cycle and apply vendor workarounds now.
Recommended defensive actions
- Upgrade to the vendor-fixed firmware version that matches your branch: 13.5.4, 13.6.3, or 13.7.7.
- For affected 13.4.1–13.4.4 systems, apply the vendor's General Mitigation Factors/Workarounds and monitor for a remediated release.
- Review certificate update procedures so changes are performed in a controlled maintenance window and only in line with vendor guidance for active connections.
- Validate whether any RTU500 CMU deployments are exposed to authenticated remote administration paths that could reach certificate-management functions.
- Use defense-in-depth controls appropriate for ICS assets, including segmentation and least-privilege administrative access.
Evidence notes
Primary evidence comes from the CISA CSAF advisory ICSA-25-093-01 for Hitachi Energy RTU500 Series (Update B), published 2025-03-25 and revised 2025-09-09. The advisory lists affected CMU Firmware versions 13.4.1–13.4.4, 13.5.1–13.5.3, 13.6.1, and 13.7.1–13.7.4, and remediation entries for 13.5.4, 13.6.3, and 13.7.7 plus general mitigation guidance. The description explicitly says the issue can be triggered when certificates are updated while in use on active connections and that the affected CMU automatically recovers after exploitation.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-11499 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-11499
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-11499 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-11499
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-093-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-093-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.