PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-2403 Hitachi Energy CVE debrief

CVE-2025-2403 is a high-severity availability issue in Hitachi Energy Relion 670/650 and SAM600-IO series devices. CISA describes it as an improper prioritization of network traffic over a protection mechanism that could let a denial-of-service condition interfere with critical functions such as the Line Distance Communication Module (LDCM). The advisory was published on 2025-06-24 and later updated on 2025-08-26 to revise fixed-version guidance.

Vendor
Hitachi Energy
Product
Relion 670
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-06-24
Original CVE updated
2025-08-26
Advisory published
2025-06-24
Advisory updated
2025-08-26

Who should care

OT and industrial control system owners, substation and protection-relay operators, utility security teams, and integrators responsible for Hitachi Energy Relion 670/650 or SAM600-IO deployments, especially where these devices support protection or communication functions.

Technical summary

The advisory identifies a network-exploitable DoS flaw with CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The stated weakness is improper prioritization of network traffic over a protection mechanism in Relion 670/650 and SAM600-IO series devices. If exploited, the issue can cause critical functions, including LDCM, to malfunction. CISA lists remediation by affected branch, including fixed releases such as 2.2.6.4, 2.2.5.8, and 2.2.4.5, plus general mitigation factors for all affected products.

Defensive priority

High

Recommended defensive actions

  • Inventory all Hitachi Energy Relion 670, Relion 650, and SAM600-IO assets and confirm exact firmware/software versions.
  • Upgrade affected systems to the vendor-fixed release for the installed branch, following the advisory guidance (for example 2.2.6.4, 2.2.5.8, or 2.2.4.5 where applicable).
  • Apply the vendor and CISA mitigation guidance for all affected products, especially if you cannot patch immediately.
  • Prioritize devices that support protection or communication functions such as LDCM for accelerated maintenance windows.
  • Review network exposure and restrict access to OT device management and traffic paths to the minimum necessary.

Evidence notes

Primary evidence comes from CISA CSAF advisory ICSA-25-182-06 (Hitachi Energy Relion 670/650 and SAM600-IO Series, Update A). The advisory states the issue is a denial of service caused by improper prioritization of network traffic over a protection mechanism and notes possible malfunction of critical functions like LDCM. The supplied CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The enrichment data indicates this is not currently marked as a CISA KEV item.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-2403 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-2403

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-2403 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-2403

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-182-06.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-182-06

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.