Hitachi Energy ITT600 Explorer
CISA says two high-severity flaws in Hitachi Energy ITT600 Explorer can trigger denial of service, with one potentially causing memory corruption. The issues affect the IEC 61850 server simulation feature and are fixed in 2.1 SP6 HF1 or later.
Intelligence analysis by GPT-5.4 Mini
CISA has issued an ICS advisory for Hitachi Energy ITT600 Explorer after finding two CVSS 7.5 vulnerabilities in libexpat used by the product. The advisory says the flaws can cause denial of service and, in some cases, memory corruption, but only when the IEC 61850 server simulation is used.
CISA found two bugs in a power-industry tool that can make it freeze or act badly, like a machine getting stuck because one tiny part breaks. The fix is to update it, and the problem only shows up when a special test mode is being used.
Analysis
What CISA reported
CISA says Hitachi Energy ITT600 Explorer is affected by two vulnerabilities in the libexpat library used by the product. Both issues are rated CVSS 7.5, and both are tied to the product’s IEC 61850 server simulation functionality.
The two issues
For CVE-2024-8176, CISA describes a stack overflow in libexpat. It says a malicious user with local access could exploit a crafted IEC 61850 message. The result could be denial of service, and in some environments it could lead to exploitable memory corruption.
For CVE-2025-59375, CISA says libexpat can be made to allocate large amounts of memory from a small document submitted for parsing. That can also lead to denial of service. CISA notes that this issue applies only if IEC 61850 server simulation is used.
Scope and remediation
The advisory says the affected product is Hitachi Energy ITT600 Explorer before version 2.1 SP6, and in one case version 2.1 SP6 and prior. Hitachi Energy lists fixes in 2.1 SP6 HF1 and says 2.2 will be available later. CISA also repeats standard industrial control system advice: limit direct internet exposure, protect process control networks with firewalls, avoid using control systems for browsing or email, and scan portable media before connecting it to operational systems.
Bottom line
This is a targeted industrial advisory rather than a broad internet-facing campaign report, but it still matters because it affects energy-sector tooling and can disrupt systems used for testing and integration if left unpatched.
Key points
- CISA issued an ICS advisory for Hitachi Energy ITT600 Explorer on June 4, 2026.
- Two CVSS 7.5 vulnerabilities affect the product's libexpat-based IEC 61850 server simulation feature.
- CISA says the bugs can cause denial of service, and one may lead to exploitable memory corruption in some environments.
- Hitachi Energy recommends updating to 2.1 SP6 HF1 or upgrading to 2.2 when available.
- The advisory emphasizes standard industrial security controls such as network segmentation and limited internet exposure.
If operators move to version 2.1 SP6 HF1 or later, the known flaws should be removed. CISA also says basic network protections and safer ICS practices can reduce exposure while systems are being patched.
If the vulnerable version stays in use, an attacker with the right access could trigger denial of service in the affected simulation feature. In the worst case described by CISA, one flaw could also lead to memory corruption depending on the environment and library usage.



