PatchSiren cyber security CVE debrief
CVE-2025-2403 Hitachi Energy CVE debrief
CVE-2025-2403 is a high-severity availability issue in Hitachi Energy Relion 670/650 and SAM600-IO series devices. CISA describes it as an improper prioritization of network traffic over a protection mechanism that could let a denial-of-service condition interfere with critical functions such as the Line Distance Communication Module (LDCM). The advisory was published on 2025-06-24 and later updated on 2025-08-26 to revise fixed-version guidance.
- Vendor
- Hitachi Energy
- Product
- Relion 670
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-24
- Original CVE updated
- 2025-08-26
- Advisory published
- 2025-06-24
- Advisory updated
- 2025-08-26
Who should care
OT and industrial control system owners, substation and protection-relay operators, utility security teams, and integrators responsible for Hitachi Energy Relion 670/650 or SAM600-IO deployments, especially where these devices support protection or communication functions.
Technical summary
The advisory identifies a network-exploitable DoS flaw with CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The stated weakness is improper prioritization of network traffic over a protection mechanism in Relion 670/650 and SAM600-IO series devices. If exploited, the issue can cause critical functions, including LDCM, to malfunction. CISA lists remediation by affected branch, including fixed releases such as 2.2.6.4, 2.2.5.8, and 2.2.4.5, plus general mitigation factors for all affected products.
Defensive priority
High
Recommended defensive actions
- Inventory all Hitachi Energy Relion 670, Relion 650, and SAM600-IO assets and confirm exact firmware/software versions.
- Upgrade affected systems to the vendor-fixed release for the installed branch, following the advisory guidance (for example 2.2.6.4, 2.2.5.8, or 2.2.4.5 where applicable).
- Apply the vendor and CISA mitigation guidance for all affected products, especially if you cannot patch immediately.
- Prioritize devices that support protection or communication functions such as LDCM for accelerated maintenance windows.
- Review network exposure and restrict access to OT device management and traffic paths to the minimum necessary.
Evidence notes
Primary evidence comes from CISA CSAF advisory ICSA-25-182-06 (Hitachi Energy Relion 670/650 and SAM600-IO Series, Update A). The advisory states the issue is a denial of service caused by improper prioritization of network traffic over a protection mechanism and notes possible malfunction of critical functions like LDCM. The supplied CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The enrichment data indicates this is not currently marked as a CISA KEV item.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-2403 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-2403
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-2403 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-2403
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-182-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-182-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.