Security/ ics-security · hitachi-energy · vulnerability · critical-infrastructure

Hitachi Energy Patches Two Open-Source Flaws in REB500 Relay

Two bugs in an open-source XML library could let an authenticated attacker crash grid-protection relays used in substations worldwide.

Hitachi Energy's REB500 protection relay has two bugs that let an authenticated attacker knock it offline.

CISA republished a Hitachi Energy advisory describing two vulnerabilities in REB500 relay versions 8.3.3.1 and earlier. Both live in libexpat, the open-source XML parser the relay uses to handle IEC 61850 substation automation messages. CVE-2024-8176 lets an authenticated, locally connected attacker send a crafted IEC 61850 message that triggers a stack overflow, crashing the device and in some configurations corrupting memory. CVE-2025-59375 lets that same kind of attacker submit a small, malformed document that forces the library to grab huge chunks of memory, also knocking the relay offline. Hitachi Energy fixes both in version 8.3.4.0.

REB500 relays protect substations, so a crash here can mean a piece of the grid loses its safety backstop, not just a frozen screen. Both bugs trace back to the same open-source parsing library rather than code Hitachi Energy wrote itself, another reminder that ICS vendors inherit risk from shared dependencies they did not author. CVSS scores land at a moderate 6.5 because exploitation needs authenticated, local access, a real barrier, but not one every utility network enforces well.

The fix is version 8.3.4.0. Everything else CISA recommends, isolating control networks, avoiding internet-facing relays, is the same advice it has given for a decade, because plenty of plants still have not taken it.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →