A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious user with local access can exploit this vulnerability using a specially crafted XML file which may lead to memory corruption and potential arbitrary code execution. Successful exploitation could result in application crashes (denial of service) and compromise the confidentiality and integrity of the affected system.
History

Wed, 27 May 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Hitachienergy
Hitachienergy mach Hidraw
Vendors & Products Hitachienergy
Hitachienergy mach Hidraw

Tue, 26 May 2026 15:30:00 +0000

Type Values Removed Values Added
Title Heap-based Buffer Overflow in HiDraw XML Parser Enables Local Code Execution

Tue, 26 May 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 26 May 2026 13:45:00 +0000

Type Values Removed Values Added
Description A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious user with local access can exploit this vulnerability using a specially crafted XML file which may lead to memory corruption and potential arbitrary code execution. Successful exploitation could result in application crashes (denial of service) and compromise the confidentiality and integrity of the affected system.
Weaknesses CWE-122
References
Metrics cvssV4_0

{'score': 4.4, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Hitachi Energy

Published: 2026-05-26T11:43:41.155Z

Updated: 2026-05-26T14:42:15.647Z

Reserved: 2026-04-28T12:37:08.600Z

Link: CVE-2026-7310

cve-icon Vulnrichment

Updated: 2026-05-26T14:42:10.307Z

cve-icon NVD

Status : Deferred

Published: 2026-05-26T14:16:40.523

Modified: 2026-05-26T20:03:50.687

Link: CVE-2026-7310

cve-icon Redhat

No data.