# Hitachi Energy APM Edge kernel LPE flaws

Published: 2026-08-13 · Severity: elevated · Sectors: energy
Canonical: https://vorant.io/reports/1a66b691-6bdd-5fda-b982-fd96ea79acd6/hitachi-energy-apm-edge-kernel-lpe-flaws

> Two Linux kernel vulnerabilities in Hitachi Energy APM Edge let local unprivileged users escalate to root privileges.

CISA republished a Hitachi Energy PSIRT advisory covering two "Dirty Frag" style vulnerabilities in the Linux kernel used by APM Edge, an energy-sector product deployed worldwide. CVE-2026-43284 affects the IPsec ESP subsystem (esp4, esp6), while CVE-2026-43500 affects the RxRPC protocol implementation (rxrpc module). Both flaws share a similar root cause: the kernel writes decrypted packet data directly into memory pages it does not own, including cached copies of privileged system binaries, allowing a local unprivileged user to inject code that later executes with root privileges when the corrupted binary runs.

Both vulnerabilities require local access and can be exploited by any local unprivileged user since the vulnerable kernel modules can be loaded without special privileges on affected APM Edge versions 6.10 and prior. Hitachi Energy's recommended mitigation is to disable the esp4/esp6 and rxrpc kernel modules respectively, rather than a patch. No evidence of active exploitation is mentioned in the advisory, and exploitation requires existing local access, limiting the immediate real-world risk despite the privilege-escalation impact.

## Mentioned in this report

- Vulnerabilities: CVE-2026-43284 (weaponized), CVE-2026-43500 (weaponized)

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-04

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1a66b691-6bdd-5fda-b982-fd96ea79acd6/hitachi-energy-apm-edge-kernel-lpe-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
