IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Hitachi Energy Asset Suite

HIGH
CVSS 8.1
Date 2026-10-06T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Hitachi Energy is aware of unauthenticated servlet access vulnerabilities that affect Asset Suite product versions listed in this document. These vulnerabilities can be exploited to potentially cause confidentiality, integrity and availability impact on the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.

// Vulnerabilities (2)

CVE ID CVSS Score Severity Description
CVE-2026-7395 8.1 high
CVE-2026-7395. Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment.
CVE-2026-11796 4.3 medium
CVE-2026-11796. Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet, which could result in denial-of-service conditions affecting application availability. These servlets are designed to perform specific functions within production environment depending on how the Asset Suite application is configured.

// Remediations (2)

Patch: Update or upgrade to Asset Suite 9.9.1 when available
Update or upgrade to Asset Suite 9.9.1 when available
Mitigation: Disable the affected servlet [2] [3] [2] HTTPPublishAdapterTestServlet is meant for testing purpose
Disable the affected servlet [2] [3] [2] HTTPPublishAdapterTestServlet is meant for testing purposes used in non-production environment [3] Functionality of the servlets, PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet to be evaluated for its utility in the production environment

// References