CVE-2024-2617 — Hitachi Energy RTU500 series CMU firmware
As of 2026-03-04, CVE-2024-2617 is a HIGH-severity vulnerability in Hitachi Energy RTU500 series CMU firmware, CVSS v3.1 7.2, EPSS 0.0% (6.7th percentile). Threadlinqs Intelligence links 2 tracked threat campaigns to CVE-2024-2617, most recently “Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran Intrusion at NCBJ Nuclear Centre, Void Manticore's Handala Persona Wipes 200,000 Stryker Devices, DragonForce Ransomware Disrupts Hazeldenes Poultry”.
Last updated: 2026-03-04
What is CVE-2024-2617?
A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if secure update feature was not enabled on all CMUs of a RTU500. If a malicious actor successfully exploits this vulnerability, they could use it to update the RTU500 with unsigned firmware.
The record classifies CVE-2024-2617 under weakness class CWE-358. Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs high-privilege credentials, needs no user interaction, and has high impact on confidentiality, integrity, availability. 1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 866 days ago.
Severity and exploitation probability
- CVSS v3.1 base score
- 7.2 — HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - EPSS (FIRST)
- 0.0% probability of exploitation in the next 30 days, higher than 6.7% of all scored CVEs
- CISA KEV
- Not listed in the CISA Known Exploited Vulnerabilities catalog
- Threadlinqs priority
- 3.9/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
- Published
- 2024-04-30, last modified 2026-03-04
Is CVE-2024-2617 being exploited?
It currently carries a trending score of 7 in the Threadlinqs vulnerability feed.
Affected products and versions
- Hitachi Energy: RTU500 series CMU firmware
How to fix CVE-2024-2617
The record marks a vendor fix as available for CVE-2024-2617. Patch reference: https://www.hitrontech.com/support/. Apply the vendor fix referenced above to every affected product listed in this record, then confirm the running version against the vendor advisory.
Threat activity tracking CVE-2024-2617
2 tracked threats in the Threadlinqs corpus reference CVE-2024-2617, either in the campaign’s CVE list or as an indicator on the campaign record.
- Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran Intrusion at NCBJ Nuclear Centre, Void Manticore's Handala Persona Wipes 200,000 Stryker Devices, DragonForce Ransomware Disrupts Hazeldenes Poultry — HIGH · 2026-09-09
- Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on Polish Energy Infrastructure — CRITICAL · 2026-02-02
Sources
Seeded from nvd and not yet processed by the Threadlinqs enrichment pipeline, so blank CVSS, EPSS or KEV fields above mean NOT MEASURED rather than measured-absent.
← all vulnerabilities · Markdown version · Threadlinqs Intelligence