CVE Database
/

CVE-2021-35534

Back to search

CVE-2021-35534

Published: Nov 18, 2021

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.1

7.2

HIGH

Description

Insufficient security control vulnerability in internal database access mechanism of Hitachi Energy Relion 670/650/SAM600-IO, Relion 650, GMS600, PWC600 allows attacker who successfully exploited this vulnerability, of which the product does not sufficiently restrict access to an internal database tables, could allow anybody with user credentials to bypass security controls that is enforced by the product. Consequently, exploitation may lead to unauthorized modifications on data/firmware, and/or to permanently disabling the product. This issue affects: Hitachi Energy Relion 670 Series 2.0 all revisions; 2.2.2 all revisions; 2.2.3 versions prior to 2.2.3.5. Hitachi Energy Relion 670/650 Series 2.1 all revisions. 2.2.0 all revisions; 2.2.4 all revisions; Hitachi Energy Relion 670/650/SAM600-IO 2.2.1 all revisions; 2.2.5 versions prior to 2.2.5.2. Hitachi Energy Relion 650 1.0 all revisions. 1.1 all revisions; 1.2 all revisions; 1.3 versions prior to 1.3.0.8; Hitachi Energy GMS600 1.3.0; 1.3.0.1; 1.2.0. Hitachi Energy PWC600 1.0.1 version 1.0.1.4 and prior versions; 1.1.0 version 1.1.0.1 and prior versions.

VendorProductVersions

Hitachi Energy

Relion 670 Series

affected
2.0 all revisions
affected
2.2.2 all revisions
affected
2.2.3 - < 2.2.3.5

Hitachi Energy

Relion 670/650 Series

affected
2.2.0 all revisions
affected
2.2.4 all revisions
affected
2.1 all revisions

Hitachi Energy

Relion 670/650/SAM600-IO

affected
2.2.1 all revisions
affected
2.2.5 - < 2.2.5.2

Hitachi Energy

Relion 650

affected
1.1 all revisions
affected
1.2 all revisions
affected
1.0 all revisions
affected
1.3 - < 1.3.0.8

Hitachi Energy

GMS600

affected
1.3.0
affected
1.3.1.0 1.3.0.1
affected
1.2.0

Hitachi Energy

PWC600

affected
1.0.1 - <= 1.0.1.4
affected
1.1.0 - <= 1.1.0.1

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

High

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now