As cited
Copy frozen at (site build).
vulnerabilities
Hitachi Energy APM Edge Product
Hitachi Energy released a security advisory covering two high-severity vulnerabilities in APM Edge product versions 6.10 and earlier that allow local privilege escalation to root. CVE-2026-43284 affects the Linux kernel's IPsec ESP subsystem (CVSS 8.8), while CVE-2026-43500 targets the RxRPC protocol implementation (CVSS 7.8), both exploitable by unprivileged local users through memory corruption techniques. Mitigation involves disabling the vulnerable kernel modules (esp4, esp6, and rxrpc) until patched versions become available.
Why it matters: Energy sector organizations running APM Edge 6.10 or earlier face privilege escalation risk from local attackers; immediate action is to assess deployment scope and disable vulnerable kernel modules or isolate systems pending patches.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Hitachi Energy APM Edge Product
Hitachi Energy released a security advisory covering two high-severity vulnerabilities in APM Edge product versions 6.10 and earlier that allow local privilege escalation to root. CVE-2026-43284 affects the Linux kernel's IPsec ESP subsystem (CVSS 8.8), while CVE-2026-43500 targets the RxRPC protocol implementation (CVSS 7.8), both exploitable by unprivileged local users through memory corruption techniques. Mitigation involves disabling the vulnerable kernel modules (esp4, esp6, and rxrpc) until patched versions become available.
Why it matters: Energy sector organizations running APM Edge 6.10 or earlier face privilege escalation risk from local attackers; immediate action is to assess deployment scope and disable vulnerable kernel modules or isolate systems pending patches.
- Source published
- First seen by Cybersecurity Tracker