CVE-2026-1772
5.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: cybersecurity@hitachienergy.com (Secondary)
Description
RTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via the RTU500 web user interface but requires further tools like browser development utilities to access them without required privileges.
Affected (20)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 12.7.1 to 12.7.7 |
| Running on/with | Platform Versions |
|---|---|
Hitachienergy Rtu520 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 12.7.1 to 12.7.7 |
| Running on/with | Platform Versions |
|---|---|
Hitachienergy Rtu530 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 12.7.1 to 12.7.7 |
| Running on/with | Platform Versions |
|---|---|
Hitachienergy Rtu540 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 12.7.1 to 12.7.7 |
| Running on/with | Platform Versions |
|---|---|
Hitachienergy Rtu560 | All versions |
References (1)
Source: cybersecurity@hitachienergy.com
Vendor Advisory
Timeline
No history available yet.