Executive brief
Hitachi Energy HiDraw, a tool used for engineering and configuring industrial control systems, contains a security flaw in how it processes XML files. An attacker with existing access to the system could use a specially crafted file to crash the application or potentially take control of the computer. This could lead to operational downtime or unauthorized access to sensitive engineering data.
Technical details
A heap-based buffer overflow (CWE-122) exists within the XML parser component of Hitachi Energy HiDraw. The vulnerability is triggered when the application processes a maliciously crafted XML file. To exploit this, an attacker must have local access to the system and valid credentials (low privilege). Successful exploitation requires user interaction, such as tricking a legitimate user into opening the malicious file, and can result in memory corruption, application crashes, or arbitrary code execution. Hitachi Energy has assigned a CVSS 4.0 score of 4.4, reflecting the requirement for local access and specific environmental conditions.
Affected products
- Hitachi Energy HiDraw
Timeline
- 2026-05-26: disclosed: Initial disclosure by Hitachi Energy and NVD publication.