$ intel.mask2.ca

ADVISORY · 2026-06-11 · SRC CISA-ADVISORIES · HIGH
2026-06-11 high REL 6/10

Hitachi Energy ITT600 Explorer vulnerabilities allow denial of service attacks

energygeneral

Hitachi Energy has disclosed two vulnerabilities in ITT600 Explorer affecting versions prior to and including 2.1 SP6. Both vulnerabilities reside in the libexpat library and can be exploited to cause denial of service through stack overflow or excessive memory allocation when IEC61850 server simulation is enabled. Mitigation involves updating to version 2.1 SP6 HF1 or awaiting version 2.2.

Why it matters in Western Canada: Energy sector organizations in Western Canada using Hitachi Energy testing tools for grid simulation and IEC61850 protocol validation should prioritize patching to prevent operational disruptions in critical infrastructure testing environments.

CVEs: CVE-2024-8176, CVE-2025-59375


Summary generated from the original advisory. Read the full source: cisa-advisories

Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-02
CVEs
CVE-2024-8176, CVE-2025-59375
Tags
hitachi-energy, itt600-explorer, dos-vulnerability, iec61850, libexpat
Provenance
mask2-ti-pipeline (AI-assisted, human-reviewable)