Hitachi Energy Asset Suite

Summary

Hitachi Energy is addressing multiple unauthenticated servlet access vulnerabilities in its Asset Suite product, specifically affecting versions 9.9.0 and prior. These vulnerabilities, including CWE-306, could allow unauthorized access to sensitive information and impact system integrity and availability.

IFF Assessment

FOE

The article describes vulnerabilities that can be exploited to compromise the confidentiality, integrity, and availability of the affected product, posing a risk to defenders.

Severity

8.1 High

The CVSS score of 8.1 reflects a critical severity, primarily due to the 'Missing Authentication for Critical Function' vulnerability (CWE-306) which allows unauthenticated access to sensitive functions with potential impacts on confidentiality, integrity, and availability.

Defender Context

Defenders should be aware of these vulnerabilities in Hitachi Energy Asset Suite, especially if deployed in critical infrastructure environments like energy. Prompt patching or mitigation, such as disabling the affected servlet, is crucial to prevent potential data disclosure and system compromise.

Read Full Story →