$ intel.mask2.ca

ADVISORY · 2026-06-11 · SRC CISA-ADVISORIES · HIGH
2026-06-11 high REL 7/10

Hitachi Energy MACH HiDraw Buffer Overflow Vulnerability (CVE-2026-7310)

energygeneral

Hitachi Energy has disclosed a heap-based buffer overflow vulnerability in MACH HiDraw versions 9.22 and earlier that could allow authenticated local users to trigger denial of service or arbitrary code execution through malicious XML files. The vulnerability affects industrial control systems used in energy infrastructure worldwide. A patched version 9.23 is available, and Hitachi recommends network segmentation and standard industrial control system security practices.

Why it matters in Western Canada: Western Canadian energy and critical infrastructure operators using Hitachi Energy MACH HiDraw for grid management or industrial control systems should assess their exposure and prioritize upgrades to version 9.23 to prevent potential compromise of power distribution and operational continuity.

CVEs: CVE-2026-7310


Summary generated from the original advisory. Read the full source: cisa-advisories

Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-05
CVEs
CVE-2026-7310
Tags
hitachi-energy, buffer-overflow, ics, critical-infrastructure, code-execution
Provenance
mask2-ti-pipeline (AI-assisted, human-reviewable)