CVE-2024-11499
CVSS 3.1 Score 4.9 of 10 (medium)
Details
Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 476
Summary
CVE-2024-11499 is a recently identified vulnerability affecting the RTU500 IEC 60870-4-104 controlled station functionality. This issue enables authenticated and authorized attackers to execute a CMU restart by exploiting a certificate updating vulnerability. The vulnerability is significant because it can be triggered during active connections, potentially causing disruptions to critical systems. Notably, once an attacker successfully exploits this vulnerability, the affected CMU will automatically recover itself.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- ABB RTU500 Remote Terminal Units
Affected Vendors
- ABB