Hitachi Energy APM Edge Product
Act NowCVSS 8.8ICS-CERT ICSA-26-225-04Jul 28, 2026
Hitachi EnergyEnergy
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Hitachi Energy APM Edge versions 6.10 and earlier contain buffer overflow vulnerabilities (CWE-787, CWE-123) in the esp4, esp6, and rxrpc kernel modules. These Dirty Frag vulnerabilities could allow a local user to execute arbitrary code with system-level privileges, compromising the confidentiality, integrity, and availability of the device.
What this means
What could happen
An attacker with local access to an APM Edge system could execute code with system-level privileges, potentially compromising the confidentiality, integrity, and availability of the entire device and any connected industrial process control systems.
Who's at risk
This vulnerability affects Hitachi Energy APM Edge systems deployed in power generation, distribution, and control environments. Operators of electrical substations, distribution centers, and grid management systems using APM Edge for data aggregation or process monitoring should prioritize mitigation.
How it could be exploited
An attacker with local or limited user-level access could exploit buffer overflow vulnerabilities (CWE-787) in the esp4, esp6, or rxrpc kernel modules to write data outside intended memory bounds. Successful exploitation would allow the attacker to execute arbitrary code with elevated privileges on the APM Edge device.
Prerequisites
- Local or low-privilege user access to the APM Edge system
- Ability to load kernel modules or trigger vulnerable code paths in esp4, esp6, or rxrpc modules
- APM Edge version 6.10 or earlier
Local exploitation requiredLow complexity attackHigh EPSS score (93.2%)Affects system availability and integrityNo patch available (mitigation only)
Exploitability
Likely to be exploited — EPSS score 93.2%
Metasploit module available — weaponized exploitView module ↗
Public Proof-of-Concept (PoC) on GitHub (10 repositories)
Affected products (1)
ProductAffected VersionsFix Status
APM Edge≤ 6.10No fix yet
Remediation & Mitigation
0/3
Do now
0/3WORKAROUNDDisable the esp4 kernel module
WORKAROUNDDisable the esp6 kernel module
WORKAROUNDDisable the rxrpc kernel module
CVEs (2)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/33ca2ad0-9061-438f-8f5e-688042486bf8Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.