{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ahitachienergyasset_suite/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hitachienergy:asset_suite:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-7395"},{"id":"CVE-2026-11796"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Asset Suite (\u003c= 9.9.0)"],"_cs_severities":["high"],"_cs_tags":["energy","ics","cve","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Hitachi Energy"],"content_html":"\u003cp\u003eHitachi Energy has identified multiple vulnerabilities in its Asset Suite product, affecting all versions up to and including 9.9.0. These flaws stem from the lack of authentication mechanisms for critical servlets, which can be reached by unauthenticated network-adjacent attackers. CVE-2026-7395 allows an attacker to interact with the HTTPPublishAdapterTestServlet, facilitating unauthorized configuration file uploads that lead to information disclosure and integrity compromise. Separately, CVE-2026-11796 exposes several other administrative servlets - including PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet, and ResourceBundleReloadServlet - allowing attackers to trigger denial-of-service conditions by disrupting application availability. These vulnerabilities affect critical energy infrastructure deployments worldwide.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify accessible web services within the target organization's industrial control network.\u003c/li\u003e\n\u003cli\u003eAttacker confirms the presence of an exposed Hitachi Energy Asset Suite web interface.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the target endpoint for the HTTPPublishAdapterTestServlet (CVE-2026-7395) or management servlets such as CacheFlushServlet (CVE-2026-11796).\u003c/li\u003e\n\u003cli\u003eAttacker sends unauthenticated HTTP GET or POST requests directly to the identified servlets.\u003c/li\u003e\n\u003cli\u003eFor CVE-2026-7395, the attacker submits a malicious configuration file to the test servlet, resulting in unauthorized file storage or disclosure.\u003c/li\u003e\n\u003cli\u003eFor CVE-2026-11796, the attacker triggers one of the reload or flush servlets, causing the application to enter a denial-of-service state.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities can lead to the loss of confidentiality and integrity of system configurations or a disruption of application availability. Given the product's use in the energy sector, such outages may impact the operational integrity of critical infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Hitachi Energy Asset Suite to version 9.9.1 or later immediately upon availability.\u003c/li\u003e\n\u003cli\u003eDisable the vulnerable servlets (HTTPPublishAdapterTestServlet, PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet, and ResourceBundleReloadServlet) if they are not required for production operations.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the Asset Suite web interface, ensuring it is isolated from the internet and placed behind firewalls with strictly controlled access policies.\u003c/li\u003e\n\u003cli\u003eImplement defense-in-depth strategies for all industrial control systems as outlined in the Hitachi Energy Industrial Control Systems Cybersecurity Best Practices notification.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T17:11:57Z","date_published":"2026-10-06T17:11:57Z","id":"https://feed.craftedsignal.io/briefs/2026-10-hitachi-asset-suite/","summary":"Hitachi Energy Asset Suite versions 9.9.0 and prior are susceptible to unauthenticated access to sensitive servlets, enabling unauthorized configuration file uploads and denial-of-service conditions.","title":"Unauthenticated Servlet Access Vulnerabilities in Hitachi Energy Asset Suite","url":"https://feed.craftedsignal.io/briefs/2026-10-hitachi-asset-suite/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:hitachienergy:asset_suite:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}