CVE-2026-7310 PUBLISHED

Assigner: Hitachi Energy
Reserved: 28.04.2026 Published: 26.05.2026 Updated: 26.05.2026

A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious user with local access can exploit this vulnerability using a specially crafted XML file which may lead to memory corruption and potential arbitrary code execution. Successful exploitation could result in application crashes (denial of service) and compromise the confidentiality and integrity of the affected system.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
CVSS Score: 4.4

Product Status

Vendor Hitachi Energy
Product MACH HiDraw
Versions Default: unaffected
  • affected from 9.0 to 9.22 (excl.)

References

Problem Types

  • CWE-122 Heap-based buffer overflow CWE

Impacts

  • CAPEC-100 Overflow Buffers