CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Hitachi Energy APM Edge Product

criticalCVE-2026-43284CVE-2026-43500
View CSAF Summary Hitachi Energy is aware of Dirty Frag vulnerabilities that affect APM Edge product versions listed in this document. Successful exploitation of these vulnerabilities could result in impact on confidentiality, integrity and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi Energy APM Edge Product are affected: APM Edge vers:APM_Edge/<=6.10 (CVE-2026-43284, CVE-2026-43500) CVSS Vendor Equipment Vulnerabilities v3 8.8 Hitachi Energy Hitachi Energy APM Edge Product Write-what-where Condition, Out-of-bounds Write Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-43284 CWE-123: Write-what-where Condition A vulnerability exists in the IPsec ESP subsystem (esp4, esp6) of the Linux kernel used in APM Edge that allows a local unprivileged user to escalate privileges to root. The flaw exists in how the kernel handles memory pages when processing ESP encrypted network packets. An attacker can craft a packet that causes the kernel to decrypt data directly into memory pages it does not own, including the cached copies of privileged operating system binaries. When one of those binaries is executed, the attacker's injected code runs with root privileges. In APM Edge, the vulnerable kernel modules (esp4, esp6) can be loaded by any local user and exploited. View CVE Details Affected Products Hitachi Energy APM Edge Product Vendor: Hitachi Energy Product Version: APM Edge versions 6.10 and prior Product Status: known_affected Remediations Mitigation Disable the esp4 and esp6 modules [2] Relevant CWE: CWE-123 Write-what-where Condition Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVE-2026-43500 CWE-787: Out-of-bounds Write A vulnerability exists in the RxRPC protocol im

CSIRTS triage

What
Dirty Frag vulnerabilities including write-what-where and out-of-bounds write conditions impact confidentiality, integrity, and availability.
Who is affected
Hitachi Energy APM Edge product version 6.10 and earlier deployments in energy critical infrastructure worldwide.
Urgency
Immediate; critical severity with CVSS 8.8 affecting multiple security properties through memory corruption.
Action
Update APM Edge to a version above 6.10 per Hitachi Energy mitigation guidance.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch APM Edge Product

Get an email when a new APM Edge Product advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-08-13
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-04

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-43284coverage & exploitation statusNVD · CVE.org
CVE-2026-43500coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from CISA Cybersecurity Advisories