Security readout for executives and security teams
Plain-English summary
A network message can make affected Hitachi Energy RTU500 CMU devices reboot if the BCI IEC 60870-5-104 function is enabled. This is an availability issue for operational technology environments. The function is disabled by default, so urgency depends on whether sites configured it and whether the device is reachable over the network.
Executive priority
Treat this as high priority where RTU500 devices support critical operations and BCI IEC 60870-5-104 is enabled. Where the feature is disabled and isolated, urgency is lower but inventory confirmation is still needed.
Technical view
CVE-2021-35533 is CWE-20 improper input validation in the APDU parser for RTU500 BCI IEC 60870-5-104. A specially crafted message can reboot a receiving CMU. Affected firmware branches are 12.0.*, 12.2.*, and 12.4.*. CVSS 3.1 is 7.5: network, low complexity, unauthenticated, no user interaction, high availability impact.
Likely exposure
Exposure is most likely in OT networks running Hitachi Energy RTU500 series CMUs on firmware 12.0.*, 12.2.*, or 12.4.* with BCI IEC 60870-5-104 enabled. Default configurations are less exposed because the affected function is disabled unless configured.
Exploitation context
The bundle does not show active exploitation, and this CVE is not marked KEV. The source indicates unauthenticated network reachability is enough when the affected BCI function is enabled. Impact is device reboot and availability disruption, not disclosed confidentiality or integrity compromise.
Researcher notes
Evidence is limited to the CVE record and vendor reference URL in the bundle. No exploit details, KEV listing, or specific fixed version is provided here. Validation should focus on affected firmware branches, BCI enablement, and network exposure.
Mitigation direction
- Confirm whether BCI IEC 60870-5-104 is required; keep it disabled if unnecessary.
- Review Hitachi Energy vendor advisory for supported remediation or firmware guidance.
- Limit network reachability to BCI-enabled RTU500 CMUs to trusted OT systems only.
- Prioritize availability monitoring for affected CMUs until remediation is confirmed.
Validation and detection
- Inventory RTU500 series CMUs and identify firmware branch and exact version.
- Verify whether BCI IEC 60870-5-104 is configured or enabled on each CMU.
- Check network paths to BCI-enabled CMUs from untrusted or routed segments.
- Review logs or monitoring for unexpected CMU reboots or availability drops.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-20: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2021-35533 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 7.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H3.93.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
7.5HighVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source materials
- CVE List V5 sourceCVE List V5
- https://search.abb.com/library/Download.aspx?DocumentID=8DBD000063&LanguageCode=en&DocumentPartId=&Action=LaunchCVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
