Hitachi Energy Asset Suite
What happened
These vulnerabilities can be exploited to potentially cause confidentiality, integrity and availability impact on the product. View CSAF Summary Hitachi Energy is aware of unauthenticated servlet access vulnerabilities that affect Asset Suite product versions listed in this document.
Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment.
These servlets are designed to perform specific functions within production environment depending on how the Asset Suite application is configured. Notice The information in this document is subject to change without notice and should not be construed as a commitment by Hitachi Energy.
Sources & evidence
- CISA Advisories Primary / official
Hitachi Energy Asset Suite โ
https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-03