Hithium · Vulnerability Disclosure

Hithium Vulnerability Disclosure

Vulnerability disclosure

Hithium publishes a vulnerability disclosure policy for reporting security issues.

CompanyEnergy StorageBatteryLithium Iron PhosphateRenewable EnergyUtilitiesManufacturingHardwareIndustrial Control Systems
Program:

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

hithium-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-22'
method: searched
source: https://www.hithium.com/support/security.html
program:
  name: HiTHIUM Cybersecurity Bulletin / PSIRT
  published: true
  team: Hithium Product Security Incident Response Team (PSIRT)
  scope: >-
    Industrial Automation and Control Systems (IACS) shipped by HiTHIUM - battery energy
    storage systems, their embedded controllers and management software. The programme is
    product/firmware scoped; it does not describe a web API or a bug bounty.
  policy_url: https://www.hithium.com/support/security.html
  report_url: https://www.hithium.com/support/security.html
  bulletin_index_url: https://www.hithium.com/support/security.html
  contact:
  - type: email
    value: IACS-CyberSecurity@hithium.com
  bug_bounty: false
  bounty_platform: null
  security_txt: false
  security_txt_note: >-
    No RFC 9116 /.well-known/security.txt is served on www.hithium.com, en.hithium.com or
    www.hero-ee.com - all three return 404. The disclosure contact is reachable only by reading
    the HTML page, so an automated scanner will not find it.
  process_standard: IEC 62443
  process_statement: >-
    "In accordance with the IEC 62443 series of standards, Hithium has established a robust
    vulnerability management process. Upon receiving a vulnerability report, we promptly provide
    users with practical and effective guidance." - verbatim from the published page.
advisories:
  format: numbered bulletins (HESSCS-YYMMNNNN), HTML detail pages, no feed
  machine_readable: false
  machine_readable_note: >-
    Bulletins are rendered from an internal CMS fragment (https://www.hithium.com/ajax/seculist,
    HTTP 200, text/html). There is no CSAF, CVRF, OSV, JSON or RSS representation, so the advisory
    stream cannot be consumed by a machine without scraping.
  count_published: 2
  entries:
  - id: HESSCS-25090001
    title: ICMP TIMESTAMP Request/Response Vulnerability
    products:
    - "∞Block 5.016MWh"
    - "∞Block 4.180MWh"
    date: '2025-09-25'
    cve:
    - CVE-1999-0524
    score: 2.1
    url: https://www.hithium.com/support/security_info/8.html
    remediation: >-
      Configure the firewall to filter incoming ICMP timestamp (type 13) packets and outgoing
      ICMP timestamp reply packets.
  - id: HESSCS-25090002
    title: Dropbear Information Disclosure Vulnerability
    products:
    - "∞Block 5.016MWh"
    - "∞Block 4.180MWh"
    date: '2025-09-22'
    cve:
    - CVE-2019-12953
    url: https://www.hithium.com/support/security.html
evidence:
- url: https://www.hithium.com/support/security.html
  status: 200
  observed: >-
    PSIRT statement, IEC 62443 reference, IACS-CyberSecurity@hithium.com contact, "Report A
    Vulnerability" call to action and the "All Cybersecurity Bulletins" table.
- url: https://www.hithium.com/ajax/seculist
  status: 200
  observed: two bulletin rows (HESSCS-25090001, HESSCS-25090002) with titles and dates
- url: https://www.hithium.com/support/security_info/8.html
  status: 200
  observed: full bulletin - description, CVSS-style score, affected firmware build, solution, 8 hardening recommendations
- url: https://www.hithium.com/.well-known/security.txt
  status: 404
- url: https://www.hero-ee.com/.well-known/security.txt
  status: 404
gaps:
- No /.well-known/security.txt, so the contact is not machine-discoverable.
- No machine-readable advisory feed (no CSAF/OSV/JSON/RSS).
- No published disclosure timeline, safe-harbour statement or acknowledgement policy.
- No PGP key or encrypted-submission channel offered.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/hithium-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.