A buffer overflow bug in Hitachi Energy's MACH HiDraw software — used in dams, power grids, and transportation infrastructure worldwide — has a fix out, but operators need to act.
The vulnerability, tracked as CVE-2026-7310, lives in the software's XML parser. An authenticated user with local access can feed it a crafted XML file, triggering a heap-based buffer overflow that can crash the application or, in a worse case, execute arbitrary code. Every version of MACH HiDraw up to and including 9.22 is affected. Hitachi Energy's own internal security team found and reported the flaw; version 9.23 resolves it. The CVSS 3.1 score sits at 5.5 — medium severity — reflecting the high attack complexity and the requirement for local access and user interaction.
The "medium" score shouldn't lull operators into inaction. Industrial control systems in critical infrastructure are precisely the targets nation-state actors and ransomware groups have been probing for years, and the barrier of "local access" is lower than it sounds in environments where contractors, USB drives, and shared workstations are routine. A crash at the wrong moment in an energy or dam control system carries consequences that dwarf anything a 5.5 CVSS score implies.
Until patching is possible, Hitachi recommends the standard ICS playbook: air-gap the network, block internet access, enforce strict removable-media policies, and use VPNs for any remote access — the same advice that has appeared in every ICS advisory for the past decade, which suggests the underlying hygiene problem remains unsolved.
