AI analysis
Hitachi Energy Asset Suite allows unauthenticated users to reach PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet, and ResourceBundleReloadServlet (CWE-306, missing authentication for a critical function). Those servlets perform maintenance actions such as flushing caches and reloading properties, metadata, or resource bundles, and invoking them can cause denial-of-service conditions that affect application availability, depending on how the product is configured. Impact is limited to availability; the CVSS 4.0 score is 5.1 (medium), with no confidentiality or integrity impact on the vulnerable system. The product is enterprise asset-management software used in energy and utility environments; affected version ranges were not stated in the provided data. No public proof-of-concept is known, and the CVE is not listed in CISA KEV.
What to do: Block unauthenticated access to PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet, and ResourceBundleReloadServlet, and keep those management endpoints off the internet and limited to trusted administrative networks. Apply Hitachi Energy’s official patch or hardening guidance for Asset Suite as soon as it is available for your deployment, and watch application logs for unexpected cache flushes or configuration reloads until the fix is in place.
Affected
| Hitachi Energy Asset Suite | — |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet, which could result in denial-of-service conditions affecting application availability. These servlets are designed to perform specific functions within production environment depending on how the Asset Suite application is configured.