Hitachi Energy ITT600 Explorer
Hitachi Energy has identified vulnerabilities in its ITT600 Explorer product, specifically versions prior to 2.1 SP6, which could lead to Denial of Service (DoS) attacks. The vulnerabilities stem from a stack overflow in the libexpat library used for IEC 61850 functionality, exploitable via crafted messages. This poses a risk to organizations utilizing the ITT600 Explorer for IEC 61850 system simulation, particularly within the energy sector.
The CISA advisory details a critical vulnerability affecting the Hitachi Energy ITT600 Explorer product. The core issue resides within the libexpat library, a component used to support IEC 61850 functionality. A malicious actor with local access could leverage a crafted IEC 61850 message to trigger a stack overflow, potentially resulting in a denial of service or, under specific circumstances, memory corruption. This vulnerability is only triggered when the ITT600 Explorer is used in conjunction with an IEC 61850 server simulation. The advisory emphasizes the importance of immediate remediation, recommending updates to version 2.1 SP6 HF1 or upgrading to version 2.2 when available. The vulnerability is classified as CVE-2024-8176 and CVE-2025-59375.