SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-17539

MEDIUM · CVSS 5.9 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The RTU500 device is vulnerable to a NULL pointer dereference caused by high-load scenarios, such as rapid GI requests, which can lead to a fatal write error and disrupt bidirectional IEC 60870-5-104 communication. This results in connection interruptions and potential denial of service. Organizations using RTU500 in critical infrastructure should prioritize addressing this vulnerability to maintain operational continuity and system reliability.

CVE
CVE-2026-17539
Severity
MEDIUM
CVSS
5.9
EPSS
0.35%

Original NVD Description

RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry of the enhanced message queue. This can cause a BCI_IEC104 fatal write error, resulting in connection interruption and restart, and ultimately a denial of service for bidirectional IEC 60870-5-104 communication.