Junglewise Threat Intelligence

CVE-2026-8479: Hitachi Energy IEC 60870-5-104 NULL pointer dereference DoS

CVE-2026-8479 · Severity: info · CVSS 6.9 · Published 2026-05-26

Vendors: Hitachi Energy.

Executive brief

A vulnerability exists in Hitachi Energy products using the IEC 60870-5-104 communication protocol, which is commonly used in electric power systems for telecontrol and monitoring. If the system is configured in bidirectional mode, an attacker could send a specific sequence of messages to crash the service. This results in a denial-of-service, potentially disrupting the monitoring and control of critical energy infrastructure.

Technical details

A NULL pointer dereference vulnerability (CWE-476) exists in the Hitachi Energy implementation of the IEC 60870-5-104 protocol. The flaw is triggered when the protocol is configured in bidirectional mode (BCI) and receives a specially crafted sequence of messages over a period of time. An attacker with adjacent network access and low privileges can exploit this to cause a crash of the affected service, resulting in a Denial of Service (DoS) impact. The vulnerability is specific to the bidirectional communication interface configuration.

Affected products

  • Hitachi Energy IEC 60870-5-104 implementation

Timeline

  • 2026-05-26: disclosed: Initial advisory publication by Hitachi Energy
  • 2026-05-26: advisory: NVD record published

References