Hitachi Energy e-mesh EMS
A buffer overflow vulnerability in Hitachi Energy e-mesh EMS versions 4.1.6, 4.4.2, and 4.7.0 allows remote exploitation through the NGINX web server component. The vulnerability could result in application outages (denial of service) or arbitrary code execution. Exploitation requires network access to the application and is more likely on systems without ASLR enabled or with rewrite configurations using "?" for unnamed captures.
- <parameter name="item">Network access to e-mesh EMS application port
Apply hotfix for respective e-mesh EMS versions to update NGINX to either v1.30.2 or latest Ensure rewrite configuration does not contain "?" to replace unnamed captures, and ensure ASLR is set to active (value=2) across all deployment targets covering all 3 versions. Underlying Ubuntu Server 20.04 LTS is End of Life. For e-mesh EMS versions 4.1.6/4.4.2 using Ubuntu 20.04 LTS, upgrade to Ubuntu Server 22.04, or 24.04, or activate Ubuntu Pro/ESM as an interim measure.
/api/v1/advisories/e51f306c-e209-4a08-ac98-63de9f1e617fGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.