CVE-2021-35533

Specially Crafted IEC 60870-5-104 Packet Vulnerability in RTU500 series

Description

Improper Input Validation vulnerability in the APDU parser in the Bidirectional Communication Interface (BCI) IEC 60870-5-104 function of Hitachi Energy RTU500 series allows an attacker to cause the receiving RTU500 CMU of which the BCI is enabled to reboot when receiving a specially crafted message. By default, BCI IEC 60870-5-104 function is disabled (not configured). This issue affects: Hitachi Energy RTU500 series CMU Firmware version 12.0.* (all versions); CMU Firmware version 12.2.* (all versions); CMU Firmware version 12.4.* (all versions).

Remediation

Solution:

  • - Disable BCI IEC 60870-5-104 function by configuration if it is not used. - Update to RTU500 series CMU Firmware version 12.6.5.0 or later (e.g., RTU500 CMU Firmware version 12.7.* or CMU Firmware version 13.2.* or later).

Category

7.5
CVSS
Severity: High
CVSS 3.1 •
CVSS 2.0 •
EPSS 0.55%
Vendor Advisory abb.com
Affected: Hitachi Energy RTU500 series
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2021-35533?
CVE-2021-35533 has been scored as a high severity vulnerability.
How to fix CVE-2021-35533?
To fix CVE-2021-35533: - Disable BCI IEC 60870-5-104 function by configuration if it is not used. - Update to RTU500 series CMU Firmware version 12.6.5.0 or later (e.g., RTU500 CMU Firmware version 12.7.* or CMU Firmware version 13.2.* or later).
Is CVE-2021-35533 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2021-35533 is being actively exploited. According to its EPSS score, there is a ~1% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2021-35533?
CVE-2021-35533 affects Hitachi Energy RTU500 series.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.