PatchSiren cyber security CVE debrief
CVE-2019-9429 Hitachi Energy CVE debrief
CISA published advisory ICSA-25-196-01 on 2025-04-29 for CVE-2019-9429. The supplied source data describes a memory corruption issue in the profman component that can trigger an out-of-bounds write and potentially lead to unauthorized local escalation of privileges. The affected product is identified in the source metadata as Asset Suite AnyWhere for Inventory (AWI) Android mobile app versions 11.5 (awi_11.5_armv7) and earlier.
- Vendor
- Hitachi Energy
- Product
- Asset Suite AnyWhere for Inventory (AWI) Android mobile app versions 11.5 (awi_11.5_armv7) and earlier
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-04-29
- Original CVE updated
- 2025-04-29
- Advisory published
- 2025-04-29
- Advisory updated
- 2025-04-29
Who should care
Administrators, application owners, and security teams responsible for Hitachi Energy Asset Suite / Asset Suite AnyWhere for Inventory (AWI), especially where affected Android endpoints are managed or exposed to local users. OT/ICS defenders should prioritize review on any systems that could allow local execution of the affected app.
Technical summary
The vulnerability is described as memory corruption in the profman component. If exploited successfully, it can cause an out-of-bounds write and result in unauthorized local privilege escalation. The supplied advisory metadata lists CVSS 3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H with a score of 7.8.
Defensive priority
High. The issue is locally exploitable and can lead to privilege escalation, so affected endpoints should be reviewed and mitigated quickly.
Recommended defensive actions
- Apply the vendor’s General Mitigation Factors/Workarounds referenced in the advisory.
- Identify whether Asset Suite AnyWhere for Inventory (AWI) Android mobile app versions 11.5 (awi_11.5_armv7) and earlier are installed in your environment.
- Restrict local access and enforce least privilege on devices that run the affected software.
- Track the vendor and CISA advisory pages for any updated remediation guidance.
- Include affected mobile endpoints in patch, configuration, and compliance verification processes.
Evidence notes
This debrief is based only on the supplied CSAF advisory metadata and linked official references. The source data explicitly states memory corruption in profman, an out-of-bounds write, and potential unauthorized local escalation of privileges. The advisory metadata also supplies the affected product scope, remediation category, and CVSS 3.1 vector; no KEV information is included in the supplied corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2019-9429 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2019-9429
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2019-9429 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-9429
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-196-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-196-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.