Hitachi Energy APM Edge Product

Summary

Hitachi Energy is aware of Dirty Frag vulnerabilities affecting APM Edge product versions 6.10 and earlier. These vulnerabilities, specifically a write-what-where condition (CVE-2026-43284) and an out-of-bounds write (CVE-2026-43500), could allow a local unprivileged user to escalate privileges to root by exploiting flaws in the Linux kernel's IPsec ESP subsystem. Successful exploitation could impact the confidentiality, integrity, and availability of the product.

IFF Assessment

FOE

The article details critical vulnerabilities that can lead to privilege escalation, posing a significant risk to defenders by allowing unauthorized access and control.

Severity

8.8 High

Defender Context

This alert highlights critical vulnerabilities in the Linux kernel's IPsec ESP subsystem affecting Hitachi Energy's APM Edge product, which is deployed in the energy sector worldwide. Defenders must be vigilant about patching or applying mitigations like disabling vulnerable kernel modules to prevent local privilege escalation to root.

Read Full Story →