Back to all lessons
Awareness Lessons
6 months ago

Critical Java Deserialization Flaw Exposes Industrial Control Systems

Hitachi Energy's Ellipse systems contain a critical vulnerability (CVE-2025-10492) in a third-party Jasper Report component that allows unauthenticated remote code execution. This Java deserialization flaw highlights the cascading security risks when third-party components contain vulnerabilities that can compromise entire industrial control systems. The CVSS 9.8 severity score reflects the potential for complete system compromise without authentication, putting critical manufacturing infrastructure at severe risk. Organizations must treat third-party component vulnerabilities with the same urgency as vulnerabilities in their primary systems.

Tactical Insight

Immediate actions

  • Apply Hitachi's recommended restrictions to limit external custom report loading to administrator-generated trusted reports only
  • Identify and inventory all Ellipse systems version 9.0.50 and prior for immediate patching priority
  • Implement network segmentation to isolate affected industrial control systems from untrusted networks

Long-term improvements

  • Establish a third-party component vulnerability management program with regular scanning and assessment
  • Maintain detailed software bill of materials (SBOM) for all industrial control systems and applications
  • Develop emergency patching procedures specifically for critical infrastructure components

Detection measures

  • Deploy network monitoring to detect unusual Java deserialization attempts or unexpected code execution
  • Enable application-level logging for Jasper Report component usage and external report loading activities