← Back to Feed

Hitachi Energy APM Edge Product

CVE-2026-43284CVE-2026-43500

August 13, 2026 · CISA (US-CERT) · Severity: CRITICAL

Hitachi Energy APM Edge 6.10 and earlier is affected by Dirty Frag vulnerabilities in the Linux kernel IPsec ESP subsystem. Locally authenticated users can exploit kernel memory handling flaws to gain root privileges and compromise the device. Hitachi Energy recommends disabling esp4 and esp6 modules until full patching guidance is applied.

Key Takeaways

  • Hitachi Energy APM Edge versions 6.10 and prior are exposed to Dirty Frag Linux kernel IPsec ESP vulnerabilities.
  • Local unprivileged attackers can escalate to root by crafting ESP packets that exploit write-what-where and out-of-bounds write flaws.
  • Impact includes loss of confidentiality, integrity, and availability; disable esp4 and esp6 modules as immediate mitigation.
☕ Buy a Coffee