PatchSiren cyber security CVE debrief
CVE-2024-3596 Hitachi Energy CVE debrief
CVE-2024-3596 is a critical RADIUS forgery issue affecting Hitachi Energy XMC20. The advisory says a valid RADIUS response under RFC 2865 can be transformed into another response type by a chosen-prefix collision attack against the MD5 Response Authenticator signature. Hitachi Energy and CISA recommend enabling the RADIUS Message-Authenticator option on both the XMC20 and the RADIUS server, and updating to XMC20 R18 where possible.
- Vendor
- Hitachi Energy
- Product
- XMC20
- CVSS
- CRITICAL 9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-05-13
- Original CVE updated
- 2026-07-07
- Advisory published
- 2025-05-13
- Advisory updated
- 2026-07-07
Who should care
Hitachi Energy XMC20 operators, OT/ICS security teams, RADIUS administrators, and responders responsible for protecting industrial control management traffic should treat this as high priority, especially where authentication traffic crosses network boundaries.
Technical summary
The source advisory describes a forgery condition in RADIUS as implemented for XMC20. Because the Response Authenticator relies on MD5, an attacker can use a chosen-prefix collision attack to convert a valid Access-Accept, Access-Reject, or Access-Challenge into a different response. The CSAF remediation notes specifically call for enabling the RADIUS Message-Authenticator option on both ends and upgrading to XMC20 R18.
Defensive priority
Critical. Prioritize patching and RADIUS hardening for any XMC20 deployment that relies on this authentication path, then reduce exposure with segmentation and ICS network controls.
Recommended defensive actions
- Update to XMC20 R18 as recommended in the vendor advisory.
- Enable the RADIUS Message-Authenticator option on both the XMC20 and the RADIUS server.
- If upgrading is not immediately possible, segment FOX management traffic to reduce risk.
- Apply ICS network hardening: minimize exposed ports, avoid direct Internet connectivity, and enforce firewall-based separation.
- Review the vendor technical documentation and PSIRT advisory for deployment-specific guidance before changing authentication settings.
Evidence notes
This debrief is based on the supplied CISA CSAF advisory ICSA-26-036-05, which was initially released on 2026-01-27 and republished/updated on 2026-02-05 with the Hitachi Energy PSIRT advisory 8DBD000233. The record names Hitachi Energy as vendor, XMC20 as the affected product, and explicitly states the RADIUS MD5 Response Authenticator forgery mechanism plus the Message-Authenticator and XMC20 R18 remediation guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-3596 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-3596
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-3596 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-3596
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-036-05.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-036-05
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.