Hitachi Energy MACH HiDraw
A buffer overflow vulnerability has been identified in Hitachi Energy’s MACH HiDraw product versions up to 9.22. Exploitation of this flaw could lead to denial-of-service attacks and potential arbitrary code execution, impacting systems within the energy and transportation sectors. Hitachi Energy is providing remediation steps, including a patched version 9.23, alongside general mitigation recommendations to protect process control networks.
The CISA advisory details a heap-based buffer overflow vulnerability within the XML parser functionality of the MACH HiDraw product. An authenticated attacker with local access can leverage a specially crafted XML file to trigger memory corruption and potentially execute arbitrary code. This vulnerability (CVE-2026-7310) poses a significant risk to systems utilizing MACH HiDraw, particularly those within critical infrastructure sectors such as dams, energy, and transportation systems. The vulnerability’s existence highlights the importance of robust security practices when handling XML data within industrial control systems.