PatchSiren

Hitachi Energy CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Hitachi Energy CVE published 2025-02-25

CVE-2024-3982

CVE-2024-3982 affects Hitachi Energy MACH GWS versions 3.0.0.0 through 3.3.0.0. CISA’s advisory says a local attacker with access to the host could enable the product’s session logging and try to hijack an already established session. The advisory also notes that session logging is disabled by default and only administrators can enable it. Hitachi Energy recommends upgrading to version 3.4.0.0 or contacti [truncated]

CRITICAL Hitachi Energy CVE published 2025-02-25

CVE-2024-3980

CVE-2024-3980 is a critical vulnerability in Hitachi Energy MACH GWS where authenticated user input can control or influence file paths or file names used in filesystem operations. If abused, that could allow access to or modification of system files or other application-critical files. CISA published the advisory on 2025-02-25 and identified affected MACH GWS versions 2.1.0.0 and 2.2.0.0 through 3.3.0.0.

MEDIUM Hitachi Energy CVE published 2025-02-25

CVE-2023-45802

CISA’s advisory for Hitachi Energy Service Suite identifies Apache HTTP Server 2.4 vulnerabilities in versions 9.8.1.3 and below. The vendor remediation is to update to version 9.8.1.4. The supplied CVSS vector points to a network-reachable issue with no privileges or user interaction required and a high availability impact. No Known Exploited Vulnerabilities (KEV) entry is included in the supplied data.

HIGH Hitachi Energy CVE published 2025-02-25

CVE-2023-43622

CVE-2023-43622 affects Hitachi Energy Service Suite versions 9.8.1.3 and below. The CISA CSAF advisory characterizes the issue as Apache HTTP Server 2.4 vulnerabilities and assigns a CVSS v3.1 score of 7.5 (High). The supplied remediation is to update to Service Suite version 9.8.1.4.

MEDIUM Hitachi Energy CVE published 2025-02-25

CVE-2023-28388

CVE-2023-28388 is a medium-severity issue published by CISA on 2025-02-25 for Hitachi Energy MACH PS700. The advisory text describes an uncontrolled search path element in some Intel(R) Chipset Device Software that may allow an authenticated local user to potentially escalate privileges. For defenders, the practical concern is exposure in affected MACH PS700 v2 System deployments where local access is alr [truncated]

CRITICAL Hitachi Energy CVE published 2025-02-25

CVE-2022-31813

CVE-2022-31813 is a critical advisory for Hitachi Energy Service Suite, published by CISA on 2025-02-25, affecting versions 9.8.1.3 and below. The supplied advisory characterizes the issue as Apache HTTP Server 2.4 vulnerabilities and recommends updating to Service Suite 9.8.1.4. The CVSS v3.1 vector indicates remote exploitation with no privileges or user interaction required and potential high impact to [truncated]

HIGH Hitachi Energy CVE published 2025-02-25

CVE-2022-30556

CVE-2022-30556 is a Hitachi Energy Service Suite advisory tied to Apache HTTP Server 2.4 vulnerabilities. The supplied CSAF data says versions 9.8.1.3 and below are affected, with a vendor fix available in Service Suite 9.8.1.4. The published CVSS 3.1 vector indicates a network-exploitable issue with no privileges or user interaction required and high confidentiality impact.

HIGH Hitachi Energy CVE published 2025-02-25

CVE-2022-30522

CVE-2022-30522 is a high-severity issue in Hitachi Energy Service Suite tied to Apache HTTP Server 2.4 vulnerabilities. The supplied CISA CSAF advisory lists versions 9.8.1.3 and below as affected and recommends upgrading to 9.8.1.4. Because the CVSS vector is network-reachable with no privileges or user interaction required and the impact is availability-only, operators should treat this as a priority pa [truncated]

HIGH Hitachi Energy CVE published 2025-02-25

CVE-2022-29404

CVE-2022-29404 is a Hitachi Energy Service Suite issue tied to Apache HTTP Server 2.4 vulnerabilities. According to the CISA CSAF advisory, affected versions are 9.8.1.3 and below, and the vendor remediation is to update to 9.8.1.4. The supplied CVSS vector shows a remotely reachable, no-authentication, no-user-interaction condition with high availability impact, so this is primarily a service-disruption [truncated]

MEDIUM Hitachi Energy CVE published 2025-02-25

CVE-2022-28614

CVE-2022-28614 is a medium-severity issue affecting Hitachi Energy Service Suite. CISA’s advisory ties the affected product to Apache HTTP Server 2.4 vulnerabilities and identifies versions 9.8.1.3 and below as impacted. Hitachi Energy lists version 9.8.1.4 as the remedation. The CVSS vector indicates a network-reachable issue with no privileges or user interaction required and low confidentiality impact.

MEDIUM Hitachi Energy CVE published 2025-02-25

CVE-2022-28330

CISA’s advisory for Hitachi Energy Service Suite identifies Apache HTTP Server 2.4 vulnerabilities affecting versions 9.8.1.3 and below. The vendor remediation is to update to version 9.8.1.4. The supplied CVSS vector indicates a network-reachable issue with low complexity and no privileges or user interaction, but the source corpus does not describe the exact Apache flaw subtype or exploit behavior.

HIGH Hitachi Energy CVE published 2025-02-25

CVE-2022-26377

CVE-2022-26377 is a HIGH-severity issue in Hitachi Energy Service Suite tied to Apache HTTP Server 2.4 vulnerabilities. CISA’s advisory, published on 2025-02-25, states that versions 9.8.1.3 and below are affected and that the vendor fix is version 9.8.1.4. The published CVSS vector indicates a network-exploitable issue that requires no privileges or user interaction and can impact integrity.

MEDIUM Hitachi Energy CVE published 2024-12-19

CVE-2023-6711

A buffer overflow vulnerability in Hitachi Energy RTU500 series CMU firmware affects SCI IEC 60870-5-104 and HCI IEC 60870-5-104 protocol implementations. Specially crafted network messages are not properly validated, which can trigger a buffer overflow and cause the RTU500 CMU to reboot. This results in a denial-of-service condition with availability impact. The vulnerability was published on December 19 [truncated]

LOW Hitachi Energy CVE published 2024-11-12

CVE-2024-41156

Hitachi Energy TRO600 series radios export configuration profiles in both plain-text and encrypted formats. Authenticated users with write access can extract these profile files, which contain sensitive network configuration details that could aid reconnaissance against Tropos networks. The vulnerability is rated LOW severity (CVSS 2.7) due to the high privilege requirement and limited confidentiality imp [truncated]

HIGH Hitachi Energy CVE published 2024-11-12

CVE-2024-41153

A command injection vulnerability in the Edge Computing UI of Hitachi Energy TRO600 series radios allows authenticated attackers with write access to the web interface to execute arbitrary system commands with root privileges. The vulnerability affects firmware versions 9.1.0.0 through 9.2.0.0 where the Edge Computing functionality is enabled. An attacker exploiting this flaw can escalate beyond their int [truncated]

MEDIUM Hitachi Energy CVE published 2024-08-27

CVE-2024-7941

CVE-2024-7941 is a medium-severity open redirect vulnerability in Hitachi Energy MicroSCADA Pro/X SYS600, published 2024-08-27 and last modified 2025-03-25. An HTTP parameter containing a URL value can cause the web application to redirect requests to attacker-specified URLs, enabling phishing attacks and credential theft. The vulnerability affects MicroSCADA X SYS600 version 10.5. Hitachi Energy released [truncated]

MEDIUM Hitachi Energy CVE published 2024-06-11

CVE-2024-28024

CVE-2024-28024 is a low-severity confidentiality issue in Hitachi Energy UNEM. According to CISA's CSAF advisory, sensitive information is stored in cleartext within a resource that might be accessible to another control sphere. The advisory lists UNEM R15A, R15B, R16A, R16B, and versions older than R15A as affected. CISA's CVSS 3.1 vector indicates local access, high privileges, and high attack complexit [truncated]

MEDIUM Hitachi Energy CVE published 2024-06-11

CVE-2024-28023

CVE-2024-28023 affects Hitachi Energy UNEM and centers on the product’s message queueing mechanism. According to the advisory corpus, successful abuse could expose resources or functionality to unintended actors and may lead to sensitive information disclosure or, in the worst case, arbitrary code execution. The issue was publicly documented on 2024-06-11 and is scored Medium (CVSS 5.7).

MEDIUM Hitachi Energy CVE published 2024-06-11

CVE-2024-28022

CVE-2024-28022 affects Hitachi Energy UNEM server / APIGateway and allows a malicious user to make an arbitrary number of authentication attempts with different passwords until the targeted account is accessed. The advisory rates the issue CVSS 6.5 (Medium) and lists affected UNEM releases including R15A, R15B, R16A, R16B, and versions older than R15A.

HIGH Hitachi Energy CVE published 2024-06-11

CVE-2024-28021

CVE-2024-28021 affects Hitachi Energy UNEM and is described as a flaw in the UNEM server/APIGateway that could allow unintended commands or code execution on the UNEM server. CISA rates the issue CVSS 8.0 HIGH, and Hitachi Energy lists multiple affected UNEM releases with version-specific remediation guidance.

HIGH Hitachi Energy CVE published 2024-06-11

CVE-2024-28020

CVE-2024-28020 is a high-severity credential reuse issue in Hitachi Energy UNEM. According to the CISA CSAF advisory and vendor reference, passwords and login information used in UNEM application and server management could be reused to extend access to the server and other services.

MEDIUM Hitachi Energy CVE published 2024-06-11

CVE-2024-2462

CVE-2024-2462 is a medium-severity issue in Hitachi Energy’s ECST client ecosystem affecting ECST, UNEM, and XMC20 versions listed in the advisory. The vendor states that, if exploited, the flaw could allow an attacker to intercept or falsify data exchanges between the client and the server. Hitachi Energy provides version-specific updates for supported releases and advises applying general mitigation fac [truncated]

MEDIUM Hitachi Energy CVE published 2024-06-11

CVE-2024-2461

CVE-2024-2461 affects Hitachi Energy XMC20 and is described as a file-system traversal issue that could let an attacker access files or directories that should be inaccessible. CISA’s advisory assigns the issue a CVSS v3.1 base score of 4.9 (Medium). Hitachi Energy recommends updating affected systems to XMC20 R16B Revision D (cent2_r16b04_07, co5ne_r16b04_07) and applying general mitigation factors; end- [truncated]

CRITICAL Hitachi Energy CVE published 2024-06-11

CVE-2024-2013

CVE-2024-2013 is a critical authentication bypass affecting Hitachi Energy UNEM server/APIGateway. According to the CISA CSAF advisory and vendor remediation guidance, unauthenticated attackers may be able to interact with services and reach post-authentication attack surface, making this a high-impact exposure for operational technology environments. The advisory lists affected UNEM versions including R1 [truncated]

CRITICAL Hitachi Energy CVE published 2024-06-11

CVE-2024-2012

CVE-2024-2012 is a critical vulnerability in Hitachi Energy UNEM’s server/APIGateway that, if exploited, could allow unintended commands or code to execute on the UNEM server. The supplied CISA CSAF advisory lists multiple affected releases and notes both fixed and planned remediation paths. No CISA KEV entry is indicated in the provided enrichment.

HIGH Hitachi Energy CVE published 2024-06-11

CVE-2024-2011

CVE-2024-2011 affects Hitachi Energy UNEM and is described as a heap-based buffer overflow that can generally lead to denial of service and may also allow arbitrary code execution. The supplied corpus rates the issue HIGH (CVSS 8.6) and shows it impacts multiple UNEM releases, including R16B PC2, R15B PC4, R16A, R15A, and versions older than R15A. Vendor guidance indicates a fix path for some branches and [truncated]

HIGH Hitachi Energy CVE published 2024-04-30

CVE-2024-2378

A privilege escalation vulnerability exists in the web-authentication component of Hitachi Energy SDM600 industrial control devices. The vulnerability, published on April 30, 2024, carries a CVSS 3.1 score of 8.0 (HIGH severity). Successful exploitation could allow an attacker to escalate privileges on affected installations. The attack vector is adjacent network-based, requiring low privileges but no use [truncated]

HIGH Hitachi Energy CVE published 2024-04-30

CVE-2024-2377

CVE-2024-2377 is a HIGH severity vulnerability (CVSS 7.6) in Hitachi Energy SDM600, published 2024-04-30. The issue stems from overly permissive HTTP response header configurations in the device's web server, which could allow an attacker to perform privileged actions and access sensitive information. The vulnerability affects SDM600 versions below 1.3.4. Hitachi Energy has released firmware version 1.3.4 [truncated]

HIGH Hitachi Energy CVE published 2024-04-30

CVE-2024-2617

CVE-2024-2617 is a HIGH severity vulnerability (CVSS 7.2) in Hitachi Energy RTU500 series CMU Firmware that allows authenticated and authorized users to bypass secure update mechanisms when the secure update feature is not enabled on all Communication and Measurement Units (CMUs) of an RTU500. Successful exploitation could enable a malicious actor to update the RTU500 with unsigned firmware, potentially c [truncated]

MEDIUM Hitachi Energy CVE published 2024-04-25

CVE-2024-1532

CVE-2024-1532 is a vulnerability in Hitachi Energy RTU500 series CMU Firmware affecting the stb-language file handling mechanism. Published on April 25, 2024, this issue allows a malicious actor to enforce diagnostic texts being displayed as empty strings when an authorized user uploads a specially crafted stb-language file. The vulnerability carries a CVSS 3.1 score of 6.8 (MEDIUM severity) with the vect [truncated]