[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fPcganiFg15bop_qFXO5pXnte9wHW3nWdiN8b6uFNzEk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"f13da36d-17bf-49db-8d9b-7687e00bd709","critical-java-deserialization-flaw-exposes-industrial-control-systems","3b68ab85-a228-4d12-87b0-e5c396a841f6","Critical Java Deserialization Flaw Exposes Industrial Control Systems","Hitachi Energy's Ellipse systems contain a critical vulnerability (CVE-2025-10492) in a third-party Jasper Report component that allows unauthenticated remote code execution. This Java deserialization flaw highlights the cascading security risks when third-party components contain vulnerabilities that can compromise entire industrial control systems. The CVSS 9.8 severity score reflects the potential for complete system compromise without authentication, putting critical manufacturing infrastructure at severe risk. Organizations must treat third-party component vulnerabilities with the same urgency as vulnerabilities in their primary systems.","**Immediate actions:**\n- Apply Hitachi's recommended restrictions to limit external custom report loading to administrator-generated trusted reports only\n- Identify and inventory all Ellipse systems version 9.0.50 and prior for immediate patching priority\n- Implement network segmentation to isolate affected industrial control systems from untrusted networks\n\n**Long-term improvements:**\n- Establish a third-party component vulnerability management program with regular scanning and assessment\n- Maintain detailed software bill of materials (SBOM) for all industrial control systems and applications\n- Develop emergency patching procedures specifically for critical infrastructure components\n\n**Detection measures:**\n- Deploy network monitoring to detect unusual Java deserialization attempts or unexpected code execution\n- Enable application-level logging for Jasper Report component usage and external report loading activities",[12,13,14,15,16],"CIS Control 7","NIST SP 800-53 SI-2","NIST Cybersecurity Framework ID.AM-2","IEC 62443-3-2","NIST SP 800-161","published","2026-04-02T19:08:23.539218+00:00","2026-04-02T19:08:23.414+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-advisories\u002Ficsa-26-092-03","hitachi-energy-ellipse","Hitachi Energy Ellipse",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":32,"name":33,"slug":34,"description":35,"color":36},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]