Impact
The vulnerability allows unauthenticated users to access an HTTPPublishAdapterTestServlet designed for testing, permitting arbitrary configuration file uploads. This flaw stems from an authentication bypass, enabling attackers to inject or replace configuration files, thereby exposing sensitive data and compromising the integrity of the system's settings.
Affected Systems
Hitachi Energy Asset Suite installations are affected. No specific version information is given, but any deployment exposing the HTTPPublishAdapterTestServlet, especially in a production environment, is vulnerable.
Risk and Exploitability
The CVSS score of 8.5 signals high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote unauthenticated access to the servlet over HTTP, inferred from the description.
OpenCVE Enrichment