Hitachi Energy REB500 Vulnerable to DoS and Memory Corruption via Crafted Messages
Hitachi Energy's REB500 product is susceptible to denial-of-service and memory corruption attacks due to two vulnerabilities in its underlying libexpat library.

Hitachi Energy has disclosed two critical vulnerabilities affecting its REB500 product, versions 8.3.3.1 and prior. These flaws, stemming from the widely used libexpat library, can be exploited by authenticated local users to disrupt system operations or cause memory corruption.
The first vulnerability, identified as CVE-2024-8176, is an uncontrolled recursion flaw within the libexpat library's IEC 61850 functionality. An attacker with local access can craft specific IEC 61850 messages to trigger this vulnerability. Depending on the environment and how the library is utilized, this exploit could lead to a denial-of-service (DoS) condition or, in more severe cases, exploitable memory corruption.
The second vulnerability, CVE-2025-59375, involves the allocation of resources without proper limits or throttling. Similar to the first, this issue resides in the libexpat library used by the REB500's IEC 61850 component. An authenticated user can exploit this by submitting a small document for parsing that triggers large, uncontrolled dynamic memory allocations, potentially leading to a denial-of-service.
Both vulnerabilities carry a CVSS v3.1 base score of 6.5, classifying them as medium severity. The attack vector is network-based (AV:N), requires low complexity (AC:L), and needs low privileges (PR:L) to exploit. The impact is primarily on availability (A:H), with no confidentiality or integrity impact.
Hitachi Energy is aware of these issues and has provided a remediation path. The company strongly recommends updating the REB500 product to version 8.3.4.0 to address these vulnerabilities. This update is expected to patch the flaws in the libexpat library and restore the product's security posture.
These vulnerabilities underscore the ongoing challenges in securing industrial control systems (ICS) that rely on open-source software components. The libexpat library, while common, has a history of security issues, highlighting the need for diligent vulnerability management and timely patching within critical infrastructure.
CISA has also issued an advisory, urging users to implement defensive measures. These include minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, and isolating them behind firewalls. Remote access should be secured via VPNs, with all components kept up-to-date.
Organizations using Hitachi Energy's REB500 product are advised to review the CISA advisory and Hitachi Energy's recommendations promptly. Applying the vendor fix is crucial to prevent potential disruptions and maintain the integrity of energy sector operations.