Hitachi Energy TXpert Hub CoreTec 4
Hitachi Energy TXpert Hub CoreTec 4 versions 2.0.0 through 2.2.1 contain multiple vulnerabilities (CWE-288 authentication issues, CWE-20 input validation, CWE-494 firmware integrity) that could allow a locally authenticated attacker with high privileges to cause denial-of-service, modify device configuration, extract sensitive information, or load malicious firmware. These vulnerabilities are not exploitable remotely and require high attack complexity, but could undermine the integrity of energy control operations if the device is compromised by an insider or through prior system compromise. Successful exploitation could disrupt process control functions managed by the hub.
- Physical or local system access to the TXpert Hub CoreTec 4 device
- High privileges (administrative level) on the device or host system
- Knowledge of or ability to exploit privilege escalation paths
Patching may require device reboot — plan for process interruption
/api/v1/advisories/1cd4d950-f47f-4102-9201-5e9bed342397Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.