← Back to home
ICSA-23-320-02  ·  Published 2023-11-16  ·  View on CISA ICS-CERT ↗

Hitachi Energy MACH System Software

CVSS 6.5 MEDIUM

Risk Summary

Successful exploitation of these vulnerabilities could allow an attacker to read/write arbitrary files without the proper authorization.

Remediations

  • Hitachi Energy recommends the following general mitigation workarounds:
  • Project recommended security practices and firewall configurations will help protect a process control network from attacks that originate from outside of the network. Such practices include that process control systems have no direct connections to the Internet; are physically protected from direct access by unauthorized personnel and are separated from other networks by means of a firewall system that has a required number of ports opened, security logs enabled, and others that have to be evaluated case by case. Process control systems should not be used for internet surfing, instant messaging, or receiving emails. Portable computers and removable storage media should be carefully scanned for viruses before they are connected to a control system.
  • Due to complexity of individual implementation of project, contact local account team for further information on possible upgrades.
  • For more information, please visit Hitachi Energy's advisory.

Affected Vendors

Hitachi Energy

Affected Products (2)

Hitachi Energy · MACH SSW >=5.0|<7.17.0.0
Hitachi Energy · MACH SSW >=7.10.0.0|<7.18.0.0

Affected Sectors

Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more