# Hitachi Energy REB500 DoS flaws disclosed

Published: 2026-10-06 · Severity: elevated · Sectors: energy
Canonical: https://vorant.io/reports/46ff8033-2bfc-5ddd-b6de-324e9455b239/hitachi-energy-reb500-dos-flaws-disclosed

> Open-source library vulnerabilities in Hitachi Energy REB500 protection relays (≤8.3.3.1) can be exploited for denial-of-service attacks on the devices.

CISA republished a Hitachi Energy PSIRT advisory covering two vulnerabilities (CVE-2024-8176, CVE-2025-59375) in open-source software components used by the REB500 bus differential protection relay product line, deployed in energy sector environments worldwide. Affected versions are REB500 ≤8.3.3.1. Successful exploitation could allow an attacker to cause a Denial of Service condition on the affected device, potentially impacting availability of protection relay functions in substation environments.

No evidence of in-the-wild exploitation is noted; these were reported internally by Hitachi Energy's own team. CISA and Hitachi Energy recommend standard ICS network hardening: minimizing network exposure of control system devices, ensuring they are not internet-accessible, isolating control networks behind firewalls, and using secure VPNs for any required remote access. Organizations should consult Hitachi Energy for patch/mitigation guidance specific to their REB500 deployment version and follow general ICS cybersecurity best practices.

This is a routine vendor vulnerability disclosure affecting a niche but critical-infrastructure-relevant product (substation protection relays) in the energy sector. Severity is assessed as medium given the DoS-only impact and lack of confirmed exploitation, though availability impact on protection relays in energy infrastructure warrants timely patching where feasible.

## Mentioned in this report

- Vulnerabilities: CVE-2024-8176, CVE-2025-59375

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-05

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/46ff8033-2bfc-5ddd-b6de-324e9455b239/hitachi-energy-reb500-dos-flaws-disclosed.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
