<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:hitachienergy:asset_suite:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ahitachienergyasset_suite/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 17:11:57 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ahitachienergyasset_suite/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Servlet Access Vulnerabilities in Hitachi Energy Asset Suite</title><link>https://feed.craftedsignal.io/briefs/2026-10-hitachi-asset-suite/</link><pubDate>Tue, 06 Oct 2026 17:11:57 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-hitachi-asset-suite/</guid><description>Hitachi Energy Asset Suite versions 9.9.0 and prior are susceptible to unauthenticated access to sensitive servlets, enabling unauthorized configuration file uploads and denial-of-service conditions.</description><content:encoded><![CDATA[<p>Hitachi Energy has identified multiple vulnerabilities in its Asset Suite product, affecting all versions up to and including 9.9.0. These flaws stem from the lack of authentication mechanisms for critical servlets, which can be reached by unauthenticated network-adjacent attackers. CVE-2026-7395 allows an attacker to interact with the HTTPPublishAdapterTestServlet, facilitating unauthorized configuration file uploads that lead to information disclosure and integrity compromise. Separately, CVE-2026-11796 exposes several other administrative servlets - including PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet, and ResourceBundleReloadServlet - allowing attackers to trigger denial-of-service conditions by disrupting application availability. These vulnerabilities affect critical energy infrastructure deployments worldwide.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs network reconnaissance to identify accessible web services within the target organization's industrial control network.</li>
<li>Attacker confirms the presence of an exposed Hitachi Energy Asset Suite web interface.</li>
<li>Attacker identifies the target endpoint for the HTTPPublishAdapterTestServlet (CVE-2026-7395) or management servlets such as CacheFlushServlet (CVE-2026-11796).</li>
<li>Attacker sends unauthenticated HTTP GET or POST requests directly to the identified servlets.</li>
<li>For CVE-2026-7395, the attacker submits a malicious configuration file to the test servlet, resulting in unauthorized file storage or disclosure.</li>
<li>For CVE-2026-11796, the attacker triggers one of the reload or flush servlets, causing the application to enter a denial-of-service state.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities can lead to the loss of confidentiality and integrity of system configurations or a disruption of application availability. Given the product's use in the energy sector, such outages may impact the operational integrity of critical infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all instances of Hitachi Energy Asset Suite to version 9.9.1 or later immediately upon availability.</li>
<li>Disable the vulnerable servlets (HTTPPublishAdapterTestServlet, PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet, and ResourceBundleReloadServlet) if they are not required for production operations.</li>
<li>Restrict network access to the Asset Suite web interface, ensuring it is isolated from the internet and placed behind firewalls with strictly controlled access policies.</li>
<li>Implement defense-in-depth strategies for all industrial control systems as outlined in the Hitachi Energy Industrial Control Systems Cybersecurity Best Practices notification.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>energy</category><category>ics</category><category>cve</category><category>vulnerability</category></item></channel></rss>