CVE-2024-2617

A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if secure update feature was not enabled on all CMUs of a RTU500. If a malicious actor successfully exploits this vulnerability, they could use it to update the RTU500 with unsigned firmware.

  • Published Apr 30, 2024
  • CVSS 7.2 high
  • 0.7% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2024-2617 at the National Vulnerability Database