AI CVE-2024-0323 affects 47 machines — VEX confirmed: Affected · Early Warning not yet filed · Due 2026-04-01 · 6:18 remaining. Open case → View VEX →
Installed base
156
machines · 23 customers
Affected machines
47
across 12 customers
Actively exploited
1
CVEs in CISA KEV catalog
Overdue obligations
0
All CRA deadlines on track
Customer notifications
12
CVE-2024-0323 · 0 / 12 sent
Showing 3 of 47 affected machines — View all →
AssetCustomerWorst severityCVEs CRA scorei% of CRA Article 14 requirements met for this machine — based on SBOM completeness, unpatched CVE count, and customer notifications sent. Below 30% = action required. SBOMLast scan
H3020
Tampere · Site A
Finjet
Critical
1CVE-2024-0323 KEVKnown Exploited · CISA KEV
CVE-2024-0323
17%
CycloneDX 1.5 3h ago
H3060
Tampere · Site A
Finjet
Critical
1CVE-2024-0323 KEVKnown Exploited · CISA KEV
CVE-2024-0323
19%
CycloneDX 1.5 3h ago
NUM P
Tampere · Site B
Finjet
Critical
1CVE-2024-0323 KEVKnown Exploited · CISA KEV
CVE-2024-0323
24%
CycloneDX 1.5 1h ago
Overdue
1
immediate action required
Pending
4
filing required
Submitted
6
this year
Next deadline
6:18
CVE-2024-0323 · Early Warning due
Reference Track Stage Status Deadline Submitted
CVE-2024-1234
OpenSSL 3.x · CVSS 8.1 · 18 machines
T1 Vuln Early Warning ⚠ Overdue Missed · 2026-03-29
INC-2026-FI-H4512
H4512 · HMI ransomware variant · Metso Corp Oulu
T2 Incident 72h Notification ● In progress 2026-04-04 · 47h 12m EW: 2026-04-02
INC-2026-FI-H3020
H3020 · Unauthorized PLC access · Finjet Oy Tampere
T2 Incident Early Warning ● Draft 2026-04-02 · 23h 37m
CVE-2024-0323
B&R Automation Runtime <Q4.93 · CVSS 9.8 · 47 machines
T1 Vuln Early Warning ⚠ Pending 2026-04-01 · 6:18
INC-2025-FI-H2201
H2201 · Unauthorized firmware modification · Outokumpu Tornio
T2 Incident Final Report 2025-12-14 2025-11-14
INC-2025-SE-H1104
H1104 · Network intrusion attempt · SSAB Sweden Luleå
T2 Incident Early Warning — Dismissed (false positive) 2025-09-03 2025-09-03
CVE-2022-42889
Apache Commons Text · CVSS 9.8
T1 Vuln Early Warning 2025-11-03 2025-11-02 · Anssi T.
CVE-2022-42889
Apache Commons Text · CVSS 9.8
T1 Vuln Detailed Report 2025-11-07 2025-11-06 · Anssi T.
Active 1
Incident Source Detected Severity Status
INC-2026-FI-H3020
Unauthorized firmware modification attempt · Outokumpu Tornio
Monitoring API 2026-03-18 Critical
Resolved · 1 incident
Incident Source Detected Severity Status
INC-2025-SE-H1104
Network intrusion attempt · SSAB Sweden Luleå
Customer report 2025-08-29 Low Dismissed
Incident details
Detected
2025-08-29 · 04:17 UTC
Source
Customer report — phone call
Machine
H1104 — Hydraulic press line B
Customer
SSAB Sweden Luleå
Description
Customer reported unusual login attempts on the machine HMI panel. IT team investigated remotely. No confirmed intrusion — attempts originated from a misconfigured internal network scanner, not an external threat actor.
CRA threshold assessment
Reviewed by
Mikael Lindqvist
Review date
2025-09-03
Severity assessed
Low
CRA Article 14 threshold
Not met — no reporting required
Threshold criteria checked
Impact on product security functions No impact confirmed
Unauthorised access to product data or controls No access gained
Impact on availability or integrity of product No impact
Significant impact on other systems or customers Isolated to single site
Dismissed — below CRA reporting threshold
No ENISA filing or customer notice required. Record retained for audit purposes.
Machine
H1104
Hydraulic press line B
SSAB Sweden Luleå
Serial: BR-H1104-SE-029
Outcome
ENISA filing Not required
Customer notice Not required
Record retained Yes
Open cases
2
1 CVE · 1 Incident
Next deadline
6:18
Early Warning · CVE-2024-0323
Machines affected
47
across 12 customers
CRA Status
Action required
Reports not yet filed
Needs attention Overdue or due this week · sorted by deadline
2 cases
CVE-2024-0323 Art. 14 §2 Early Warning pending
Actively exploited · CVSS 9.8 · 47 machines across 12 customers · EW due 2026-04-01
6:18
remaining
INC-2026-FI-H3020 Art. 14 §3 Early Warning pending
Finjet Oy · Tampere · Unauthorized PLC access
23:37
remaining
All open cases
2 cases
Progress reflects 5 compliance steps: Early Warning → 72h Report → Final Report → Customer Notice → Closure
Case Type Customer Progress Next deadline Next step
CVE-2024-0323
B&R Automation Runtime <Q4.93 · CVSS 9.8 · 47 machines
CVE
12 customers
Finjet, Konecranes, Valmet +9
0 / 5
2026-04-01 · 6:18 Early Warning pending
INC-2026-FI-H3020
Unauthorized PLC access · H3020
Incident
Finjet Oy
Tampere
0 / 5
2026-04-02 · 23h 37m Early Warning pending
ENISA Reporting
Early Warning — Action Needed
File Early Warning with ENISA
Due 2026-04-01 · 6:18 remaining · CRA Article 14 §2
72h Detailed Report — Pending
File detailed report with ENISA
Unlocks after Early Warning is filed · Due within 72h of detection
Customer Notification
Initial Notice — Action needed
Notify all affected customers
12 customers · 0 / 12 sent · Required without undue delay · CRA Article 14
WO-2342 M. Korhonen · Open
Patch not yet published
Publishing unlocks Final Report (ENISA) and Closure Report (customers)
Final Report — Pending
File final report with ENISA
Due 14 days after patch published · Unlocks when patch is published
Closure Report — Pending
Confirm resolution to all customers
Available after patch published · Confirms patch availability + case closure
Close case — OEM obligations fulfilled
Complete both tracks above · CRA Article 13 & 14
Affected machines
H3020
Finjet · Tampere
CRC-2200
Konecranes · Helsinki
+45 more machines →
Linked work orders
WO-2341
File Early Warning with ENISA
Open
WO-2342
Customer notices
Open
72h Report · Final Report · Closure
Steps 3–5
Not created
Machine status
Live · IoT
Patch deployment
0 / 47
Awaiting patch publication — will update automatically on check-in
Connectivity
Live / connected 39
Not connected 8
Synced via IoT module. Patch deployment tracks automatically once patch is published. Case closure does not require full deployment.
VEX confirmed — 2026-03-31 09:14 UTC · AI-generated and reviewed by A. Virtanen · Read only · Case opened from this assessment →
AI VEX status determined automatically from SBOM component match, asset network configuration, and CISA KEV data. All evidence fields below are sourced from live asset and SBOM records. A. Virtanen reviewed and confirmed before the case was opened.
1 — VEX determination
AI filled
CVE-2024-0323
Affected
High — all required data points present
A. Virtanen · 2026-03-31 09:14 UTC
Component version confirmed in SBOM, attack vector is network-reachable with no authentication required, no compensating controls detected. Contextual risk matches NVD score.
2 — AI evidence & reasoning
AI filled
Component match
B&R Automation Runtime
< Q4.93
Q4.92 — within affected range ✗
2026-03-31 08:47 UTC
Attack vector reachability
Network (AV:N) — no physical access required
None (PR:N / UI:N)
Exposed — port 21 open, reachable from automation network ✗
Network-connected (always-on) · IoT module active
Compensating controls
None detected ✗
Flat automation network — no VLAN isolation on this asset
Not configured on this segment
No mitigating controls reduce exploitability ✗
CVSS contextual assessment
9.8 Critical — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 — no environmental reduction applies
Active exploitation confirmed — in CISA KEV catalog ✗
0.001 · 73rd percentile
3 — Formal VEX statement
H3020 Machine Controller · Rev. C
B&R Automation Runtime Q4.92
affected
Upgrade Automation Runtime to Q4.93 or later. Block FTP port 21 at network boundary as interim mitigation.
A heap-based buffer overflow in the FTP server component of B&R Automation Runtime Q4.92 is reachable from the automation network without authentication. Exploitation could allow an unauthenticated remote attacker to execute arbitrary code with runtime process privileges on H3020. Confidentiality, integrity, and availability of the controller are at risk.
4 — Compliance implications
Yes — actively exploited, Critical severity · CRA Article 14 §2
2026-04-01 09:14 UTC · within 24h of awareness
Yes — 12 affected customers · without undue delay
Within 7 days for actively exploited CVEs · CRA Article 14 §4
§1 (no known exploitable vulns), §2 (secure by default), §10 (patch without undue delay)
2026-03-31 09:14 UTC · View case →
ENISA Reporting
Early Warning — Action needed
File Early Warning with authorities
Due 2026-04-02 14:23 UTC · 23h 37m remaining
WO-2356 A. Virtanen · Open
72h Notification — Pending
File 72h detailed notification
Due within 72h of detection · Available after Early Warning filed
Customer Notification
Initial Notice — Action needed
Notify affected customer
1 customer — Finjet Oy · Required without undue delay · CRA Article 14
WO-2357 M. Korhonen · Open
Incident not yet contained
Confirming H3020 is secured unlocks Final Report (ENISA) and Confirm resolved (customer)
Final Report — Pending
File final report with ENISA
Due within 1 month of containment · Unlocks when incident is contained
Confirm Resolved — Pending
Confirm incident resolved to customer
Available after incident contained · Confirms H3020 is secured
Close case
Available when all ENISA reports filed and customer confirmed resolved
AI Guidance Content below is AI-generated from the incident record — click any text to edit directly. Review carefully before sending — machine access incidents require precise language.
Security Incident Notice
INC-2026-FI-H3020 · Finjet Oy · H3020 · Initial notice · 2026-04-02
Executive summary AI
We are writing to inform you of a security incident detected on 2026-04-02 affecting machine H3020 at your Tampere facility. An unauthorized access attempt to the PLC was identified. We are investigating the nature and scope of the access. This notification is provided under our obligations under the EU Cyber Resilience Act (Article 14).
1
Machine affected
H3020
Asset ID
2026-04-02
Detection date
Active
Investigation
What happened
AI filled
Unauthorized PLC access detected on H3020
On 2026-04-02, our monitoring systems detected an unauthorized access attempt targeting the PLC on machine H3020 at your Tampere site. The access originated from an unexpected network source. We have logged the event and initiated a full investigation. We are currently assessing whether any configuration changes or data were affected.
Actions taken
AI filled
Investigation initiated — machine being assessed
We have notified the relevant authorities (ENISA Early Warning filed) and assigned a dedicated work order (WO-2356) to A. Virtanen for investigation. Network access logs from H3020 have been preserved. We are working to confirm the full scope and will provide an update within 72 hours.
Recommended steps for you
No immediate action is required from your side at this stage. Please do not modify the machine configuration or restart H3020 until you receive further instructions from us — this preserves the state needed for our investigation. We will contact you within 72 hours with a full update.
AI-generated content — review before sending
AI-generated content — review before sending
Reports filed
3
to authorities this year
Notices sent
2
to customers this year
Last submission
06 Nov 2025
CVE-2022-42889 Detailed Report
Active cases 1
Case Stage Type Submitted Recipient
CVE-2024-0323
B&R Automation Runtime <Q4.93
Customer Notice Customer notice 2025-10-20 Andritz AG
CVE-2024-0323
B&R Automation Runtime <Q4.93
72h Report Security report 2025-09-28 ENISA
CVE-2024-0323
B&R Automation Runtime <Q4.93
Early Warning Security report 2025-09-25 ENISA
Closed · 2 cases
Case Stage Type Submitted Recipient
INC-2025-SE-H1104
Network intrusion attempt · SSAB Sweden Luleå
Dismissed Assessment record 2025-09-03 Internal
Sent to Andritz AG — 2025-10-20 · CRA Article 14 §8 · Sent by M. Korhonen · Read only
Recipients
Andritz AG
security@andritz.com
AND-0047 · AND-0048 · AND-0051 (3 installations)
M. Korhonen · WO-2342
Notice content
Security Notice — CVE-2024-0323 affecting B&R Automation Runtime installations
A critical vulnerability (CVE-2024-0323, CVSS 9.8) has been identified in B&R Automation Runtime <Q4.93. A heap-based buffer overflow in the FTP server component allows an unauthenticated remote attacker to potentially execute arbitrary code on affected controllers. 3 of your installations are affected.
A patch will be made available via your customer portal at portal.fter.io. You will receive a follow-up notice with download instructions once the patch is released. No action is required from your side at this stage — we will notify you when the patch is ready to deploy.
Patch expected: 2025-10-28 · Closure notice to follow after patch confirmed deployed
Send details
Executive summary
Email · security@andritz.com
Submitted to ENISA — 2026-04-01 09:56 UTC · Filed on time · Reference: ENISA-2026-FI-00847 · Read only
1 — Incident identification
CVE-2024-0323
2026-03-31 09:14 UTC
Critical (CVSS 9.8)
Actively exploited in the wild
A heap-based buffer overflow vulnerability exists in the FTP server component of B&R Automation Runtime. An unauthenticated remote attacker can send a specially crafted FTP request that exceeds an internal buffer boundary, potentially enabling arbitrary code execution on the affected controller. Root weakness: CWE-122.
2 — Affected products & installations
B&R Industrial Automation GmbH
B&R Automation Runtime
<Q4.93
47 (across 12 customers)
AssetCustomerSiteComponent version
H3020Finjet OyTampereAutomation Runtime Q4.92
H3060Finjet OyTampereAutomation Runtime Q4.92
KCR-2241KonecranesHyvinkääAutomation Runtime Q4.92
VLM-0118ValmetJyväskyläAutomation Runtime Q4.91
AND-0047AndritzGrazAutomation Runtime Q4.90
Showing 5 of 47 — full list included in submission
3 — Initial impact & mitigation
Confidentiality — data interception
Patch preparation in progress
Vulnerability identified via SBOM scan. Affected components mapped to 47 installations. Patch development initiated. Customers to be notified per CRA Article 14 requirements.
4 — Notifier information
Fter Technologies Oy
A. Virtanen
security@fter.io
Finland
Submitted to ENISA — 2026-04-07 11:24 UTC · 4 days late · Deadline was 2026-04-03 · Reference: ENISA-2026-FI-00847-DR · Read only
1 — Incident identification
CVE-2024-0323
ENISA-2026-FI-00847
9.8 — Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Yes — confirmed in the wild
2 — Root cause & technical detail
Heap-based buffer overflow in FTP server component
CWE-122 — Heap-based Buffer Overflow
The FTP server component in B&R Automation Runtime <Q4.93 contains a heap-based buffer overflow vulnerability (CWE-122). An unauthenticated remote attacker can send a specially crafted FTP request that exceeds an internal buffer boundary, overwriting adjacent memory and potentially enabling arbitrary code execution with the privileges of the runtime process. No authentication or prior access is required. Successful exploitation may result in full compromise of the affected controller.
Yes — SBOM updated 2026-04-01
47 installations · 12 customers
3 — Impact assessment
High — memory disclosure may expose sensitive data and credentials
High — transferred files may be tampered
High — successful exploitation can crash or fully compromise the runtime process
Observed in targeted campaigns against industrial control systems
Risk is highest for installations where the Automation Runtime FTP port is reachable from untrusted network segments. Successful exploitation allows an attacker to execute arbitrary code with runtime process privileges, posing a risk to confidentiality, integrity, and availability of the controller. No confirmed exploitation of affected customer installations as of filing date.
4 — Remediation plan
In development — target release 2026-04-14
2026-04-21
Patch Q4.93 corrects the heap-based buffer overflow in the FTP server component, preventing arbitrary code execution. Final Report to be filed by 2026-04-21.
Coordinated — 90 day disclosure window
Yes — after patch available to all customers
Initial notice sent to 12 customers — 2026-04-07
Draft prepared — to be published after patch release
Submitted to ENISA — 2026-04-21 09:42 UTC · On time · Reference: ENISA-2026-FI-00847-FR · Case closed · Read only
1 — Incident resolution
Fully resolved — all installations patched
B&R Automation Runtime Q4.93
2026-04-14 (published) · 2026-04-21 (all customers confirmed)
47 / 47 — 100% remediated
Patch Q4.93 corrects the resource locking logic in the SDM service handler, ensuring concurrent connections are serialized correctly. All 47 affected installations confirmed patched by 2026-04-21. No customer reported any service interruption attributable to exploitation of this vulnerability prior to patching.
2 — Root cause (confirmed)
Concurrent access to shared SDM handler state not protected by a lock — race condition introduced during Q4.x branch refactoring
Yes — same pattern present in 3 other components (addressed in Q4.93)
The SDM handler was refactored in the Q4.90 release to improve throughput under concurrent load, but the locking discipline was not carried over from the prior implementation. Automated regression tests did not cover concurrent SDM stress scenarios. The flaw remained dormant until B&R published advisory SA25P002 in March 2026. SBOM cross-referencing with NVD triggered detection on 2026-03-31.
3 — Customer notification
Yes — all 12 affected customers
2026-04-07
2026-04-21
Yes — published 2026-04-21 at fter.io/security/SA-2026-001
4 — Lessons learned
1. Legacy protocol support must be reviewed during each release cycle and deprecated on a defined schedule. 2. SBOM scanning now integrated into CI/CD pipeline — cryptographic primitive checks added to automated security gates. 3. Vulnerability response workflow improved: 72h report delayed due to unclear ownership of ENISA filing. Responsibility now documented in security runbook. 4. Customer notification template updated to remove pre-filled mitigation claims not verified by OEM.
CWE-122 scan added to SBOM pipeline. Protocol deprecation policy documented. Security runbook updated with CRA reporting responsibility matrix. ENISA filing rehearsal scheduled for Q3 2026.
Early Warning
Submitted 2026-04-01 09:56 UTC
Submitted
72h Detailed Report
Submitted 2026-04-03 11:24 UTC
Submitted
Final Report
Submitted 2026-04-21 09:42 UTC
Submitted
Authority reporting steps only · View full case (5 steps) →
CRA Article 14 — Reporting obligation triggered. CVE-2024-0323 has a known active exploit. Early Warning must be submitted to ENISA within 24 hours of detection.
18:42
Early Warning
66:42
Detailed Report
1
Early Warning
Due within 24h of becoming aware
Pending
2
72h Detailed Report
Available after Early Warning submitted
Upcoming
3
Final Report
Due 14 days after patch available
Upcoming
Authority reporting steps only · View full case (5 steps) →
AI Guidance Fields marked AI have been pre-filled from your SBOM and asset data. Review before submitting — you are legally responsible for accuracy.
1 — Incident identification
AI filled
2 — Affected products & installations
AI filled
Affected assets in installed base
Showing 5 of 47Export full list
AssetCustomerSiteComponent versionStatus
H3020Finjet OyTampereAutomation Runtime Q4.92Open
H3060Finjet OyTampereAutomation Runtime Q4.92Open
KCR-2241KonecranesHyvinkääAutomation Runtime Q4.92Open
VLM-0118ValmetJyväskyläAutomation Runtime Q4.91Open
AND-0047AndritzGrazAutomation Runtime Q4.90Open
3 — Initial impact & mitigation
4 — Notifier information
72h Detailed Report — available after Early Warning is submitted
Submit the Early Warning above to unlock this step.
1
Initial Notice
Action needed · CRA Article 14 §8
Pending
2
Closure Notice
Send after patch is available
Upcoming
Customer notification steps only · View full case (5 steps) →
AI Guidance Content below is AI-generated — click any text to edit directly if it needs adjusting. Choose tone to match your audience — Executive for management, Technical for IT teams.
Security Status Report
CVE-2024-0323 · 12 customers · 47 affected installations · Initial notice · 2026-04-07
Executive summary AI
We are writing to inform you of a critical cybersecurity vulnerability (CVE-2024-0323) detected in the B&R Automation Runtime component installed in your equipment. The vulnerability enables a remote attacker to cause the affected controller to stop responding by sending crafted protocol messages. Immediate remediation is in progress and we expect full resolution within 14 days. No operational disruption has occurred. This notification is provided under our obligations under the EU Cyber Resilience Act (Article 14).
1
Critical CVE
47
Affected installations
12
Customers to notify
14
Days to resolve
Our remediation status
Patch under development — B&R Automation Runtime Q4.93
CVE-2024-0323 · Target availability 2026-04-07 · Will be published for customer download on completion
Recommended next steps for your team
AI
1
Forward this notice to your IT/OT security team — they will need to be aware and plan a maintenance window for applying the patch once it becomes available.
2
Plan a maintenance window for patching your affected machines. The patch will be ready for you to download and apply — we will send download instructions in our closure report.
3
Watch for our closure report — when the patch is published we will send you download instructions and confirm the case is resolved. No action is needed from you until then.
Recipients · 12 customers ✓ 11 contacts found ⚠ 1 missing
Customer Contact email Installations
Finjet Oy
security@finjet.fi 6 machines ✓ Ready
Andritz AG
it-security@andritz.com 8 machines ✓ Ready
Konecranes Oyj
Contact not on file 3 machines
SSAB Sweden AB
cyber@ssab.com 12 machines ✓ Ready
Metso Corporation
security@metso.com 4 machines ✓ Ready
+ 7 more customers · all contacts found →
Konecranes Oyj will not receive this notice — contact missing. Add a contact or proceed and log the gap in your audit trail.
AI-generated content — review before sending
Initial Notice
Sent 2026-04-07 · 12 / 12 delivered
Sent
2
Closure Notice
Action needed · Patch Q4.93 published 2026-04-07
Pending
Customer notification steps only · View full case (5 steps) →
AI Guidance Content below is AI-generated — click any text to edit directly if it needs adjusting. Fill in how customers can get the patch — that is the only required field before sending.
Security Resolution Report
CVE-2024-0323 · 12 customers · 47 installations · Patch published 2026-04-07
Resolution summary AI
We are writing to confirm that the critical cybersecurity vulnerability CVE-2024-0323 affecting your equipment has been fully resolved. A patch for the B&R Automation Runtime component is now available and ready to apply. No data was compromised and no operational disruption occurred. This report is provided under our obligations under the EU Cyber Resilience Act (Article 14).
1
CVE resolved
47
Installations patched
12
Customers notified
6d
Time to resolve
How customers get the patch
Required to send
This text will appear as a highlighted block in the email. All other content is generated automatically.
What was resolved
B&R Automation Runtime patched to Q4.93
CVE-2024-0323 · CVSS 9.8 · FTP buffer overflow patched · Published 2026-04-07
Action required from your team
AI
1
Download and apply the patch using the instructions provided above. The patch resolves CVE-2024-0323 in B&R Automation Runtime and should be applied at your earliest convenience.
2
Plan a maintenance window if your process requires downtime for patching. The patch itself takes approximately 15 minutes per machine.
3
Confirm patch applied to your internal IT/OT team. No response back to us is required — your CRA obligations as an operator are met by applying the available patch.
Recipients · 12 customers ✓ 11 contacts found ⚠ 1 missing
Customer Contact email Installations
Finjet Oy
security@finjet.fi 6 machines ✓ Ready
Andritz AG
it-security@andritz.com 8 machines ✓ Ready
Konecranes Oyj
Contact not on file 3 machines
SSAB Sweden AB
cyber@ssab.com 12 machines ✓ Ready
Metso Corporation
security@metso.com 4 machines ✓ Ready
+ 7 more customers · all contacts found →
Konecranes Oyj will not receive this report — contact missing. Add a contact or proceed and log the gap in your audit trail.
AI-generated content — review before sending
24h Early Warning required — CRA Article 14 §3. Monitoring flagged a severe security incident on H3020 at Finjet Oy Tampere at 14:23 UTC. Triage and confirm below, then submit Early Warning to CSIRT and ENISA.
23:37
Early Warning
1
24h Early Warning
Due 2026-04-02 14:23 UTC
Pending
2
72h Notification
Available after Early Warning submitted
Upcoming
3
Final Report
Due 1 month after 72h notification
Upcoming
Authority reporting steps only · View full case (5 steps) →
Monitoring Alert H3020 · Finjet Oy · Tampere — received 2026-04-01 14:21 UTC. Monitoring detected unauthorized PLC parameter modifications and a remote connection from 192.168.1.47 (not in known device registry). Parameters modified: feed rate limits and axis home positions. No safety systems affected. Activity pattern is consistent with unauthorized remote access. AI assessment: likely criminal/malicious intent. Awareness timestamp auto-logged: 2026-04-01 14:23 UTC — not editable.
Triage — confirm incident type
Required before reporting
AI Guidance This qualifies as a severe security incident under CRA Article 14 §3. Unauthorized control access has a direct impact on product security. The 24h Early Warning clock is running from 14:23 UTC. Confirm to start the reporting flow, or dismiss if this is an operational anomaly. Dismissals are logged for audit.
INC-2026-FI-H4512 — HMI Ransomware Variant
H4512 · Metso Corp · Oulu, FI · Awareness logged 2026-04-02 09:10 UTC
Awareness: 2026-04-02 09:10 UTC — auto-logged
Early Warning submitted. 72h Incident Notification due by 2026-04-04 09:11 UTC — 47h 12m remaining. Complete Stage 2 below.
24h Early Warning
Submitted 2026-04-02 09:11 UTC
Submitted
2
72h Incident Notification
Due 2026-04-04 09:11 UTC
Pending
3
Final Report
1 month from 72h submission
Locked
Stage 2 — 72h Incident Notification
CRA Article 14 §4(b)
AI Pre-fill Notification pre-filled from monitoring data and asset registry. Review all sections carefully — this is a legally binding submission.
A — Incident description & severity
B — Mitigations taken
C — Customer notification
AI Draft Customer notification drafted below. CRA Article 14 §8 requires you to inform affected users without undue delay.
Stage 3 — Final Report unlocks after 72h Notification submission