LiveActive security incident?Get immediate response
CVE Record

CVE-2021-35533: Specially Crafted IEC 60870-5-104 Packet Vulnerability in RTU500 series

Improper Input Validation vulnerability in the APDU parser in the Bidirectional Communication Interface (BCI) IEC 60870-5-104 function of Hitachi Energy RTU500 series allows an attacker to cause the receiving RTU500 CMU of which the BCI is enabled to reboot when receiving a specially crafted message. By default, BCI IEC 60870-5-104 function is disabled (not configured). This issue affects: Hitachi Energy RTU500 series CMU Firmware version 12.0.* (all versions); CMU Firmware version 12.2.* (all versions); CMU Firmware version 12.4.* (all versions).

HighCVSS 7.5Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

A network message can make affected Hitachi Energy RTU500 CMU devices reboot if the BCI IEC 60870-5-104 function is enabled. This is an availability issue for operational technology environments. The function is disabled by default, so urgency depends on whether sites configured it and whether the device is reachable over the network.

Executive priority

Treat this as high priority where RTU500 devices support critical operations and BCI IEC 60870-5-104 is enabled. Where the feature is disabled and isolated, urgency is lower but inventory confirmation is still needed.

Technical view

CVE-2021-35533 is CWE-20 improper input validation in the APDU parser for RTU500 BCI IEC 60870-5-104. A specially crafted message can reboot a receiving CMU. Affected firmware branches are 12.0.*, 12.2.*, and 12.4.*. CVSS 3.1 is 7.5: network, low complexity, unauthenticated, no user interaction, high availability impact.

Likely exposure

Exposure is most likely in OT networks running Hitachi Energy RTU500 series CMUs on firmware 12.0.*, 12.2.*, or 12.4.* with BCI IEC 60870-5-104 enabled. Default configurations are less exposed because the affected function is disabled unless configured.

Exploitation context

The bundle does not show active exploitation, and this CVE is not marked KEV. The source indicates unauthenticated network reachability is enough when the affected BCI function is enabled. Impact is device reboot and availability disruption, not disclosed confidentiality or integrity compromise.

Researcher notes

Evidence is limited to the CVE record and vendor reference URL in the bundle. No exploit details, KEV listing, or specific fixed version is provided here. Validation should focus on affected firmware branches, BCI enablement, and network exposure.

Mitigation direction

  • Confirm whether BCI IEC 60870-5-104 is required; keep it disabled if unnecessary.
  • Review Hitachi Energy vendor advisory for supported remediation or firmware guidance.
  • Limit network reachability to BCI-enabled RTU500 CMUs to trusted OT systems only.
  • Prioritize availability monitoring for affected CMUs until remediation is confirmed.

Validation and detection

  • Inventory RTU500 series CMUs and identify firmware branch and exact version.
  • Verify whether BCI IEC 60870-5-104 is configured or enabled on each CMU.
  • Check network paths to BCI-enabled CMUs from untrusted or routed segments.
  • Review logs or monitoring for unexpected CMU reboots or availability drops.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-20: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-35533 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.5 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.5CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H3.93.6Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

7.5High
CVSS 3.1 vector shape for CVE-2021-35533Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Hitachi EnergyRTU500 seriesCMU Firmware version 12.0, CMU Firmware version 12.2, CMU Firmware version 12.4Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.