Hitachi Energy SOI Vulnerability Alert
Hitachi Energy SOI Vulnerability Alert
Hitachi Energy is aware of a Remote Code Execution (RCE) vulnerability in the Apache ActiveMQ component of the SOI product. This vulnerability affects the following versions: SOI >= 2.0.0 and <= 2.2.0 (CVE-2026-34197). ⚠️ The affected Critical Infrastructure Sectors include Energy, with deployments worldwide.
The Hitachi Energy Internal Team reported this vulnerability to CISA.
Recommended Security Practices
To protect a process control network from external attacks, consider the following security practices:
- Ensure process control systems are physically protected from unauthorized access.
- Avoid direct connections to the Internet.
- Use firewalls to separate networks, minimizing exposed ports.
- Do not use process control systems for Internet surfing, instant messaging, or receiving emails.
- Scan portable computers and removable storage for viruses before connecting them to control systems.
- Follow proper password policies and processes.
For more information on Industrial Control Systems Cybersecurity Best Practices, refer to Hitachi Energy’s Cybersecurity Notification.
Defensive Measures
CISA recommends users take defensive measures to minimize the risk of exploitation:
- Minimize network exposure for all control system devices.
- Ensure they are not accessible from the Internet.
- Isolate control system networks and remote devices behind firewalls.
- Use secure methods like Virtual Private Networks (VPNs) for remote access, while keeping in mind that VPNs may have vulnerabilities.
CISA also provides a section for control systems security recommended practices on the ICS webpage. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
For more details, read the complete article here.