Hitachi Energy APM Edge Product
View CSAF Summary Hitachi Energy is aware of Dirty Frag vulnerabilities that affect APM Edge product versions listed in this document. Successful exploitation of these vulnerabilities could result in impact on confidentiality, integrity and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi Energy APM Edge Product are affected: APM Edge vers:APM_Edge/<=6.10 (CVE-2026-43284, CVE-2026-43500) CVSS Vendor Equipment Vulnerabilities v3 8.8 Hitachi Energy Hitachi Energy APM Edge Product Write-what-where Condition, Out-of-bounds Write Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-43284 CWE-123: Write-what-where Condition A vulnerability exists in the IPsec ESP subsystem (esp4, esp6) of the Linux kernel used in APM Edge that allows a local unprivileged user to escalate privileges to root. The flaw exists in how the kernel handles memory pages when processing ESP encrypted network packets. An attacker can craft a packet that causes the kernel to decrypt data directly into memory pages it does not own, including the cached copies of privileged operating system binaries. When one of those binaries is executed, the attacker's injected code runs with root privileges. In APM Edge, the vulnerable kernel modules (esp4, esp6) can be loaded by any local user and exploited. View CVE Details Affected Products Hitachi Energy APM Edge Product Vendor: Hitachi Energy Product Version: APM Edge versions 6.10 and prior Product Status: known_affected Remediations Mitigation Disable the esp4 and esp6 modules [2] Relevant CWE: CWE-123 Write-what-where Condition Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVE-2026-43500 CWE-787: Out-of-bounds Write A vulnerability exists in the RxRPC protocol im
CSIRTS triage
- What
- Dirty Frag vulnerabilities including write-what-where and out-of-bounds write conditions impact confidentiality, integrity, and availability.
- Who is affected
- Hitachi Energy APM Edge product version 6.10 and earlier deployments in energy critical infrastructure worldwide.
- Urgency
- Immediate; critical severity with CVSS 8.8 affecting multiple security properties through memory corruption.
- Action
- Update APM Edge to a version above 6.10 per Hitachi Energy mitigation guidance.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch APM Edge Product
Get an email when a new APM Edge Product advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-04
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation likely imminentCVE-2026-43284EPSS puts this in the most-targeted tier (93.2% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99.8% of all EPSS-scored CVEs.
- Exploitation likely imminentCVE-2026-43500EPSS puts this in the most-targeted tier (92.9% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99.8% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-43284 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-43500 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploited[UPDATE] [high] Linux Kernel: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Ubuntu Linux kernel (August 14, 2026)cert-fr-avis
- unknownUSN-8530-2: Linux kernel (HWE) vulnerabilitiesubuntu
- highexploited[UPDATE] [high] Linux Kernel (Dirty Frag): Multiple vulnerabilities allow gaining administrator rightscert-bund
- unknownMultiple vulnerabilities in SUSE Linux kernel (July 31, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Red Hat Linux kernel (July 31, 2026)cert-fr-avis
- unknownexploitedSiemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFPcisa
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund
- unknownUSN-8616-1: Linux kernel (IBM) vulnerabilitiesubuntu
- highUSN-8569-1: Linux kernel (HWE) vulnerabilitiesubuntu
- unknownMultiple vulnerabilities in the SUSE Linux kernel (July 17, 2026)cert-fr-avis
- unknownUSN-8530-1: Linux kernel (AWS) vulnerabilitiesubuntu
More from CISA Cybersecurity Advisories
- criticalJohnson Controls Metasys2026-08-13
- criticalSiemens Siveillance Video2026-08-13
- criticalFlow Neuroscience FL-1002026-08-13
- criticalSiemens LOGO! Soft Comfort2026-08-13
- criticalJohnson Controls Inc. Airwall2026-08-13