CVE-2024-8176
View CSAF Summary Hitachi Energy is aware of vulnerabilities that affect ITT600 Explorer product versions listed in this document. These vulnerabilities can be exploited to carry out Denial of Serv...
Affects 0 products across 2 vendors.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A stack overflow vulnerability in the libexpat library can be exploited by deeply nested entity references in XML documents, leading to a denial of service (DoS) or potential memory corruption. This affects Fujitsu-Siemens and Siemens products, with a CVSS score of 7.5, indicating a high risk of availability impact.
BSID: BS-2025-GLOBAL-041779-H • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2024-8176?
What is the CVSS score for CVE-2024-8176?
Is CVE-2024-8176 actively exploited?
How do I remediate CVE-2024-8176?
What systems are affected by CVE-2024-8176?
What NERC-CIP standard applies to CVE-2024-8176?
What IEC 62443 requirement maps to CVE-2024-8176?
| CVE ID | CVE-2024-8176 |
|---|---|
| BSID | BS-2025-GLOBAL-041779-H BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| Published | 2026-06-04 |
| Last Modified | 2026-06-04 |
| ICS Relevance | 55% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
View CSAF Summary Hitachi Energy is aware of vulnerabilities that affect ITT600 Explorer product versions listed in this document. These vulnerabilities can be exploited to carry out Denial of Service (DoS) attack on the product. The vulnerabilities only affect Hitachi Energy Integrated Testing Tool ITT600 SA Explorer without affecting IEC 61850 system endpoints. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi
Source: NIST NVD / MITRE CVE Database
The vulnerability can be triggered by an attacker sending a specially crafted XML document with deeply nested entity references to a system using the libexpat library. This can cause the library to exhaust stack space, leading to a crash or memory corruption. The attack can be performed remotely without authentication, making it particularly dangerous in networked environments.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Fujitsu-Siemens | — | — |
| Siemens | — | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement input validation and limit the depth of entity references in XML documents processed by the libexpat library. Consider using a more secure XML parser that is less susceptible to such attacks.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 because it can lead to a denial of service, which could impact the availability of critical cyber assets in the electric power system.
This CVE maps to SR 7.6 because it involves a vulnerability that can be exploited to cause a denial of service, which is a critical security concern in ICS environments.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 47e227eb26dde9365e32fbbe0f18dcf5cd753847f36080122c6023ea14d7057a8689a40ad632ecf461d34c853baf94d6902b83ebaa05b0c5cc8f437bec4d3457 |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →