Vulnerabilities found in Hitachi Energy's TRMTracker product, with a CVSS v4 score of 6.9, could allow an attacker to execute limited remote commands, poison the web cache, or disclose and modify sensitive information. These affect versions 6.2.04 and earlier, as well as versions 6.3.0 and 6.3.01 of TRMTracker. Vulnerabilities include LDAP injection, injection into output used by a downstream component, and cross-site scripting. Hitachi Energy advises users to update to recommended versions, implement security practices and firewall configurations, and follow proper password policies. Organizations are recommended to follow best cybersecurity practices to proactively defend industrial control system assets.





