CVE-2024-8176

HIGH

View CSAF Summary Hitachi Energy is aware of vulnerabilities that affect ITT600 Explorer product versions listed in this document. These vulnerabilities can be exploited to carry out Denial of Serv...

Affects 0 products across 2 vendors.

BCS6.99
CVSS 3.17.5
EPSS1.6%
Percentile73th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, no confidentiality impact, no integrity impact, full availability impact.
CWE Weakness Definitions
CWE-674: CWE-674
Related Attack Patterns (CAPEC)
CAPEC-230 Serialized Data with Nested Payloads
via CWE-674
CAPEC-231 Oversized Serialized Data Payloads
via CWE-674

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A stack overflow vulnerability in the libexpat library can be exploited by deeply nested entity references in XML documents, leading to a denial of service (DoS) or potential memory corruption. This affects Fujitsu-Siemens and Siemens products, with a CVSS score of 7.5, indicating a high risk of availability impact.

BSID: BS-2025-GLOBAL-041779-H • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-8176?
A stack overflow vulnerability in the libexpat library can be exploited by deeply nested entity references in XML documents, leading to a denial of service (DoS) or potential memory corruption. This affects Fujitsu-Siemens and Siemens products, with a CVSS score of 7.5, indicating a high risk of availability impact.
What is the CVSS score for CVE-2024-8176?
CVE-2024-8176 has CVSS 7.5 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. EPSS: 1.6%.
Is CVE-2024-8176 actively exploited?
No confirmed active exploitation of CVE-2024-8176 as of 2026-06-05.
How do I remediate CVE-2024-8176?
Priority: MEDIUM. Advisory: https://access.redhat.com/security/cve/CVE-2024-8176
What systems are affected by CVE-2024-8176?
CVE-2024-8176 affects: Fujitsu-Siemens, Siemens.
What NERC-CIP standard applies to CVE-2024-8176?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 because it can lead to a denial of service, which could impact the availability of critical cyber assets in the electric power system.
What IEC 62443 requirement maps to CVE-2024-8176?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves a vulnerability that can be exploited to cause a denial of service, which is a critical security concern in ICS environments.
Vulnerability Details
CVE IDCVE-2024-8176
BSIDBS-2025-GLOBAL-041779-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Published2026-06-04
Last Modified2026-06-04
ICS Relevance55%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

View CSAF Summary Hitachi Energy is aware of vulnerabilities that affect ITT600 Explorer product versions listed in this document. These vulnerabilities can be exploited to carry out Denial of Service (DoS) attack on the product. The vulnerabilities only affect Hitachi Energy Integrated Testing Tool ITT600 SA Explorer without affecting IEC 61850 system endpoints. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability can be triggered by an attacker sending a specially crafted XML document with deeply nested entity references to a system using the libexpat library. This can cause the library to exhaust stack space, leading to a crash or memory corruption. The attack can be performed remotely without authentication, making it particularly dangerous in networked environments.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Fujitsu-Siemens —
Siemens —
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 51 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement input validation and limit the depth of entity references in XML documents processed by the libexpat library. Consider using a more secure XML parser that is less susceptible to such attacks.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 because it can lead to a denial of service, which could impact the availability of critical cyber assets in the electric power system.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves a vulnerability that can be exploited to cause a denial of service, which is a critical security concern in ICS environments.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash47e227eb26dde9365e32fbbe0f18dcf5cd753847f36080122c6023ea14d7057a8689a40ad632ecf461d34c853baf94d6902b83ebaa05b0c5cc8f437bec4d3457
Related CVEs affecting Fujitsu-Siemens
CVE-2024-32741 10.0 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0).... CVE-2024-44102 10.0 A vulnerability has been identified in PP TeleControl Server Basic 1000 to 50... CVE-2008-5810 10.0 WBPublish (aka WBPublish.exe) in Fujitsu-Siemens WebTransactions 7.0, 7.1, an... CVE-2024-30207 10.0 A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780... CVE-2025-32433 10.0 Erlang/OTP is a set of libraries for the Erlang programming language. Prior t...
View all Fujitsu-Siemens CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →