← Back to home
ICSA-23-059-02  ·  Published 2023-03-06  ·  View on CISA ICS-CERT ↗

Hitachi Energy Gateway Station

CVSS 7.5 HIGH

Risk Summary

Successful exploitation of these vulnerabilities could cause part of GWS fail to start, allow unauthorized actors to run scripts, and/or cause a denial-of-service.

Remediations

  • Hitachi Energy has created an update to address the reported vulnerabilities and recommends users update to at least GWS version 3.3.0.0
  • Hitachi Energy recommends the following general mitigation factors and security practices:
  • Configure firewalls to protect process control networks from attacks originating from outside the network
  • Physically protect process control systems from direct access by unauthorized personnel
  • Avoid directly connecting control systems to the internet
  • Separate process control networks from other networks using a firewall system with a minimal number of ports exposed
  • Process control systems should not be used for internet surfing, instant messaging, or receiving emails
  • Portable computers and removable storage media should be carefully scanned for viruses before connecting to a control system
  • Enforce proper password policies and processes
  • For more information, see Hitachi security advisory 8DBD000116.

Affected Vendors

Hitachi Energy

Affected Products (3)

Hitachi Energy · Gateway Station (GWS) 3.0.0.0
Hitachi Energy · Gateway Station (GWS) 3.1.0.0
Hitachi Energy · Gateway Station (GWS) 3.2.0.0

Affected Sectors

Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more