PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-43622 Hitachi Energy CVE debrief

CVE-2023-43622 affects Hitachi Energy Service Suite versions 9.8.1.3 and below. The CISA CSAF advisory characterizes the issue as Apache HTTP Server 2.4 vulnerabilities and assigns a CVSS v3.1 score of 7.5 (High). The supplied remediation is to update to Service Suite version 9.8.1.4.

Vendor
Hitachi Energy
Product
Service Suite
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-02-25
Original CVE updated
2025-02-25
Advisory published
2025-02-25
Advisory updated
2025-02-25

Who should care

Organizations running Hitachi Energy Service Suite 9.8.1.3 or earlier, especially OT/ICS operators, platform administrators, and security teams responsible for patching and validating industrial software.

Technical summary

The advisory ties the weakness to Apache HTTP Server 2.4 vulnerabilities in Hitachi Energy Service Suite. The supplied CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) indicates a network-reachable issue that requires no privileges or user interaction and can cause high availability impact. The supplied source does not provide a more granular Apache CVE breakdown, so the safest public summary is limited to the advisory scope and affected version range.

Defensive priority

High. The issue is remotely reachable, requires no authentication, is rated 7.5/High, and has a clear vendor fix (upgrade to 9.8.1.4). Prioritize it for any deployed instance at or below 9.8.1.3.

Recommended defensive actions

  • Inventory Hitachi Energy Service Suite deployments and confirm whether any instance is version 9.8.1.3 or below.
  • Upgrade affected systems to version 9.8.1.4 as directed by the vendor advisory.
  • Validate service availability and dependent OT workflows after patching, especially where Service Suite supports critical operations.
  • Review CISA industrial control system recommended practices and maintain segmentation, least privilege, and defense-in-depth controls around the service.
  • Monitor vendor and CISA advisories for any follow-up guidance or additional component-specific details.

Evidence notes

The supplied CISA CSAF advisory (ICSA-25-133-01) published on 2025-02-25 identifies Hitachi Energy Service Suite versions 9.8.1.3 and below as affected and recommends updating to 9.8.1.4. The metadata also records the issue as Apache HTTP Server 2.4 vulnerabilities and provides CVSS v3.1 vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. No KEV entry is present in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-43622 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-43622

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-43622 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-43622

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-133-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-133-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.