generated: '2026-08-22' method: searched source: https://www.hithium.com/support/security.html program: name: HiTHIUM Cybersecurity Bulletin / PSIRT published: true team: Hithium Product Security Incident Response Team (PSIRT) scope: >- Industrial Automation and Control Systems (IACS) shipped by HiTHIUM - battery energy storage systems, their embedded controllers and management software. The programme is product/firmware scoped; it does not describe a web API or a bug bounty. policy_url: https://www.hithium.com/support/security.html report_url: https://www.hithium.com/support/security.html bulletin_index_url: https://www.hithium.com/support/security.html contact: - type: email value: IACS-CyberSecurity@hithium.com bug_bounty: false bounty_platform: null security_txt: false security_txt_note: >- No RFC 9116 /.well-known/security.txt is served on www.hithium.com, en.hithium.com or www.hero-ee.com - all three return 404. The disclosure contact is reachable only by reading the HTML page, so an automated scanner will not find it. process_standard: IEC 62443 process_statement: >- "In accordance with the IEC 62443 series of standards, Hithium has established a robust vulnerability management process. Upon receiving a vulnerability report, we promptly provide users with practical and effective guidance." - verbatim from the published page. advisories: format: numbered bulletins (HESSCS-YYMMNNNN), HTML detail pages, no feed machine_readable: false machine_readable_note: >- Bulletins are rendered from an internal CMS fragment (https://www.hithium.com/ajax/seculist, HTTP 200, text/html). There is no CSAF, CVRF, OSV, JSON or RSS representation, so the advisory stream cannot be consumed by a machine without scraping. count_published: 2 entries: - id: HESSCS-25090001 title: ICMP TIMESTAMP Request/Response Vulnerability products: - "∞Block 5.016MWh" - "∞Block 4.180MWh" date: '2025-09-25' cve: - CVE-1999-0524 score: 2.1 url: https://www.hithium.com/support/security_info/8.html remediation: >- Configure the firewall to filter incoming ICMP timestamp (type 13) packets and outgoing ICMP timestamp reply packets. - id: HESSCS-25090002 title: Dropbear Information Disclosure Vulnerability products: - "∞Block 5.016MWh" - "∞Block 4.180MWh" date: '2025-09-22' cve: - CVE-2019-12953 url: https://www.hithium.com/support/security.html evidence: - url: https://www.hithium.com/support/security.html status: 200 observed: >- PSIRT statement, IEC 62443 reference, IACS-CyberSecurity@hithium.com contact, "Report A Vulnerability" call to action and the "All Cybersecurity Bulletins" table. - url: https://www.hithium.com/ajax/seculist status: 200 observed: two bulletin rows (HESSCS-25090001, HESSCS-25090002) with titles and dates - url: https://www.hithium.com/support/security_info/8.html status: 200 observed: full bulletin - description, CVSS-style score, affected firmware build, solution, 8 hardening recommendations - url: https://www.hithium.com/.well-known/security.txt status: 404 - url: https://www.hero-ee.com/.well-known/security.txt status: 404 gaps: - No /.well-known/security.txt, so the contact is not machine-discoverable. - No machine-readable advisory feed (no CSAF/OSV/JSON/RSS). - No published disclosure timeline, safe-harbour statement or acknowledgement policy. - No PGP key or encrypted-submission channel offered.