[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-hitachi-energy-patches-two-open-source-flaws-in-reb500-relay":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},10377,"hitachi-energy-patches-two-open-source-flaws-in-reb500-relay","Hitachi Energy Patches Two Open-Source Flaws in REB500 Relay","Two bugs in an open-source XML library could let an authenticated attacker crash grid-protection relays used in substations worldwide.","Hitachi Energy's REB500 protection relay has two bugs that let an authenticated attacker knock it offline.\n\nCISA republished a Hitachi Energy advisory describing two vulnerabilities in REB500 relay versions 8.3.3.1 and earlier. Both live in libexpat, the open-source XML parser the relay uses to handle IEC 61850 substation automation messages. CVE-2024-8176 lets an authenticated, locally connected attacker send a crafted IEC 61850 message that triggers a stack overflow, crashing the device and in some configurations corrupting memory. CVE-2025-59375 lets that same kind of attacker submit a small, malformed document that forces the library to grab huge chunks of memory, also knocking the relay offline. Hitachi Energy fixes both in version 8.3.4.0.\n\nREB500 relays protect substations, so a crash here can mean a piece of the grid loses its safety backstop, not just a frozen screen. Both bugs trace back to the same open-source parsing library rather than code Hitachi Energy wrote itself, another reminder that ICS vendors inherit risk from shared dependencies they did not author. CVSS scores land at a moderate 6.5 because exploitation needs authenticated, local access, a real barrier, but not one every utility network enforces well.\n\nThe fix is version 8.3.4.0. Everything else CISA recommends, isolating control networks, avoiding internet-facing relays, is the same advice it has given for a decade, because plenty of plants still have not taken it.","[\"ics-security\",\"hitachi-energy\",\"vulnerability\",\"critical-infrastructure\"]","2026-10-06T12:00:00.000Z","2026-10-07T01:02:00.055Z","2026-10-07T01:02:05.710Z","published",null,[],"security",[26,27,28,29],"ics-security","hitachi-energy","vulnerability","critical-infrastructure",[31],{"name":32,"url":33},"CISA Advisories","https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-advisories\u002Ficsa-26-279-05",0,{"sections":36},[37,42,46,51,56,61,66,71,76,81,86,91,95,100],{"name":38,"slug":39,"count":40,"latest_published_at":41},"AI","ai",6357,"2026-10-06T17:28:33.000Z",{"name":43,"slug":24,"count":44,"latest_published_at":45},"Security",892,"2026-10-06T17:50:11.000Z",{"name":47,"slug":48,"count":49,"latest_published_at":50},"Policy","policy",468,"2026-10-06T17:01:52.000Z",{"name":52,"slug":53,"count":54,"latest_published_at":55},"Deals","deals",406,"2026-10-06T18:26:53.000Z",{"name":57,"slug":58,"count":59,"latest_published_at":60},"Hardware","hardware",216,"2026-10-06T18:22:57.000Z",{"name":62,"slug":63,"count":64,"latest_published_at":65},"Science","science",184,"2026-10-06T18:10:45.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":70},"Consumer Tech","consumer-tech",165,"2026-10-06T17:31:59.000Z",{"name":72,"slug":73,"count":74,"latest_published_at":75},"Software","software",109,"2026-10-06T17:06:24.000Z",{"name":77,"slug":78,"count":79,"latest_published_at":80},"Startups","startups",105,"2026-10-06T16:29:12.000Z",{"name":82,"slug":83,"count":84,"latest_published_at":85},"Dev Tools","dev-tools",103,"2026-10-06T17:20:00.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":90},"Gaming","gaming",55,"2026-10-06T09:38:03.000Z",{"name":92,"slug":93,"count":89,"latest_published_at":94},"General","general","2026-10-06T13:57:32.000Z",{"name":96,"slug":97,"count":98,"latest_published_at":99},"Reviews","reviews",33,"2026-10-05T11:57:17.000Z",{"name":101,"slug":102,"count":103,"latest_published_at":104},"How-To","how-to",8,"2026-10-05T09:00:00.000Z"]