Hitachi Energy has several vulnerabilities in its TRMTracker product that could allow an attacker to execute limited remote commands, poison the web cache, or disclose and modify sensitive information. Affected product versions are TRMTracker: 6.2.04 and earlier, as well as 6.3.0 and 6.3.01. Vulnerabilities include LDAP injection, host header injection, and cross-site scripting. Eskom Holdings SOC Ltd of South Africa reported these vulnerabilities to Hitachi Energy. Users are recommended to update to the following versions: v6.2.04.014 or v6.3.02 for TRMTracker Versions 6.2.04 and earlier, and v6.3.02 for TRMTracker Versions 6.3.0 and 6.3.01. Hitachi Energy also suggests implementing recommended security practices and firewall configurations to protect the process control network. For more information, refer to the associated Hitachi Energy PSIRT 8DBD000210 Cybersecurity Advisory - Multiple Vulnerabilities in Hitachi Energy TRMTracker product.





