news.mlab.sh
Back to the feed
vulnerability

Hitachi Energy e-mesh EMS

High
Summary

Hitachi Energy has identified a buffer overflow vulnerability within its e-mesh EMS product versions 4.1.6, 4.4.2, and 4.7.0, stemming from a flaw in the NGINX Plus and NGINX Open Source modules. Exploitation could lead to denial of service and potential arbitrary code execution, particularly when using vulnerable versions of NGINX (v1.30.0 and below). The vendor recommends applying a hotfix to update NGINX to version 1.30.2 or later, and implementing mitigations such as ensuring rewrite configurations do not include question marks in replacement strings and enabling Address Space Layout Randomization (ASLR).

Read the full article at CISA Advisories

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.