PatchSiren cyber security CVE debrief
CVE-2024-28757 Hitachi Energy CVE debrief
CVE-2024-28757 is a medium-severity availability issue in Hitachi Energy RTU500 series components that use libexpat for IEC 61850 client and server processing. According to the CISA CSAF advisory published on 2025-09-16, an authenticated and authorized malicious user could load crafted XML input that may cause memory mismanagement and potentially reboot the RTU500. Hitachi Energy’s remediation guidance calls out a firmware update for CMU Firmware 13.7.1 through 13.7.6 to version 13.7.7, along with general mitigation factors/workarounds. The practical risk is operational disruption rather than code execution or data theft: the described impact is device reboot, which can interrupt control availability in industrial environments. Organizations running the RTU500 series should treat this as a priority maintenance item wherever the affected CMU firmware range is deployed and authenticated access to IEC 61850 interfaces exists.
- Vendor
- Hitachi Energy
- Product
- Unknown
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-09-16
- Original CVE updated
- 2025-09-16
- Advisory published
- 2025-09-16
- Advisory updated
- 2025-09-16
Who should care
OT/ICS operators, control engineers, and security teams responsible for Hitachi Energy RTU500 deployments—especially systems running CMU Firmware 13.7.1 through 13.7.6 and exposing IEC 61850 client/server functionality to authenticated users.
Technical summary
The advisory describes a libexpat-related memory mismanagement condition in the IEC 61850 client and server components of the RTU500 product series. A successful trigger requires an authenticated and authorized malicious user to supply crafted XML input. The stated outcome is a reboot of RTU500, so the primary security impact is availability loss. The provided CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) aligns with a network-reachable, low-complexity, low-privilege, no-user-interaction availability issue. Hitachi Energy’s listed remediation is to update CMU Firmware 13.7.1 through 13.7.6 to 13.7.7 and follow the associated mitigation guidance.
Defensive priority
Medium-high. The vulnerability is not described as remotely unauthenticated, but it can still interrupt industrial operations by rebooting affected RTU500 systems. Prioritize if the affected firmware range is deployed in production or where IEC 61850 interfaces are reachable by authorized users.
Recommended defensive actions
- Upgrade RTU500 series CMU Firmware version 13.7.1 through 13.7.6 to CMU Firmware version 13.7.7, as specified by Hitachi Energy.
- Review and apply the general mitigation factors/workarounds referenced in the vendor advisory for CVE-2024-28757.
- Limit and monitor authenticated access to IEC 61850 client/server functions and XML-bearing workflows on affected RTU500 systems.
- Validate operational resilience, including failover and reboot recovery procedures, before and after remediation.
Evidence notes
This debrief is based on the CISA CSAF advisory for ICSA-25-259-02 and the CVE record metadata supplied in the source corpus. The core claims used here are limited to the advisory description: libexpat use in RTU500 IEC 61850 client/server components, crafted XML input from an authenticated and authorized malicious user, memory mismanagement, and possible reboot. Remediation details are taken from the advisory’s listed mitigation entries, including the CMU Firmware 13.7.7 update path for versions 13.7.1 through 13.7.6. No exploitation evidence, KEV listing, or threat-campaign attribution was supplied.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-28757 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-28757
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-28757 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-28757
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-259-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-259-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.