CVE-2024-10037 - CVE House
Back to Database
Status published Medium CVE-2024-10037

A vulnerability exists in the RTU500 web server component that...

Vulnerability Description

A vulnerability exists in the RTU500 web server component that can cause a denial of service to the RTU500 CMU application if a specially crafted message sequence is executed on a WebSocket connection. An attacker must be properly authenticated and the test mode function of RTU500 must be enabled to exploit this vulnerability. The affected CMU will automatically recover itself if an attacker successfully exploits this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-10037

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Hitachi Energy

View all reports →

Affected Software

RTU500
Vulnerable Versions:
12.0.1, 12.2.1, 12.4.1, 12.6.1, 12.7.1, 13.2.1, 13.4.1, 13.5.1, 13.6.1, 12.7.8, 13.7.1

Timeline

Official Publish: March 25th, 2025
Last Modified: March 31st, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)