VYPR
advisoryPublished Oct 6, 2026· 1 source

Hitachi Energy Asset Suite Vulnerable to Information Disclosure and Denial-of-Service Attacks

CISA alerts to two critical vulnerabilities in Hitachi Energy's Asset Suite, versions prior to 9.9.1, enabling unauthenticated attackers to compromise system integrity and availability.

Hitachi Energy's Asset Suite, a critical component for managing energy assets, is facing significant security risks due to two newly disclosed vulnerabilities. CISA has issued an advisory detailing these flaws, which affect versions 9.9.0 and earlier. The vulnerabilities, identified as CVE-2026-7395 and CVE-2026-11796, could allow unauthenticated attackers to gain unauthorized access to sensitive information or disrupt system operations.

CVE-2026-7395 specifically targets the HTTPPublishAdapterTestServlet, a diagnostic tool intended for non-production environments. When accessible without authentication, this servlet can be exploited by attackers to upload configuration files. This capability can lead to a compromise of system integrity and the disclosure of confidential information. The severity of this vulnerability is rated as HIGH with a CVSS score of 8.1.

The second vulnerability, CVE-2026-11796, impacts several other servlets: PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet, and ResourceBundleReloadServlet. Exploitation of these servlets can result in denial-of-service (DoS) conditions, rendering the Asset Suite application unavailable. While these servlets are designed for specific functions within production environments, their unauthenticated access poses a significant risk to the availability of critical energy infrastructure.

The CVSS score for CVE-2026-11796 is rated as MEDIUM at 4.3, reflecting its potential to disrupt operations. Both vulnerabilities stem from a common root cause: missing authentication for critical functions, categorized under CWE-306. This highlights a systemic issue in how these diagnostic and management servlets were exposed.

Hitachi Energy has acknowledged these vulnerabilities and is working on a resolution. A vendor fix is available in Asset Suite version 9.9.1. In the interim, organizations are advised to disable the affected servlets, particularly the HTTPPublishAdapterTestServlet, which should not be present in production environments. Further evaluation of the utility of the other affected servlets in production is also recommended.

These vulnerabilities were reported to CISA by EDF, underscoring the collaborative efforts in identifying and mitigating risks within the industrial control systems (ICS) sector. The widespread deployment of Hitachi Energy's Asset Suite across the global energy sector makes these vulnerabilities a matter of significant concern for critical infrastructure security.

Beyond the immediate vendor fix and mitigation strategies, CISA also provides general recommendations for securing process control networks. These include physical security measures, network segmentation with minimal exposed ports, avoiding internet browsing on control systems, and rigorous scanning of removable media for malware. Adherence to proper password policies is also crucial.

The disclosure of these vulnerabilities serves as a stark reminder of the ongoing security challenges facing the energy sector and the importance of timely patching and robust security practices for industrial control systems. The potential for information disclosure and denial-of-service attacks in such critical infrastructure necessitates swift action from affected organizations.

Synthesized by Vypr AI