CVE-2026-1772 PUBLISHED

Assigner: Hitachi Energy
Reserved: 02.02.2026 Published: 24.02.2026 Updated: 24.02.2026

RTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via the RTU500 web user interface but requires further tools like browser development utilities to access them without required privileges.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor Hitachi Energy
Product RTU500 series CMU firmware
Versions Default: unaffected
  • affected from 12.7.1 to 12.7.7 (incl.)
  • affected from 13.5.1 to 13.5.4 (incl.)
  • affected from 13.6.1 to 13.6.2 (incl.)
  • affected from 13.7.1 to 13.7.7 (incl.)
  • Version 13.8.1 is affected

References

Problem Types

  • CWE-280 Improper Handling of Insufficient Permissions or Privileges CWE

Impacts

  • CAPEC-503 WebView Exposure