PT-2021-20953 · Hitachi Abb Power Grids · Hitachi Abb Power Grids Esoms

Published

2021-07-14

·

Updated

2023-05-16

·

CVE-2021-35527

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Hitachi ABB Power Grids eSOMS versions prior to 6.3
Description: The issue is related to a password autocomplete vulnerability in the web application password field, allowing an attacker to gain access to user credentials stored by the browser.
Recommendations: For Hitachi ABB Power Grids eSOMS versions prior to 6.3, consider disabling the password autocomplete feature in the web application password field as a temporary workaround until a patch is available. Restrict access to sensitive areas of the application to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2021-35527

Affected Products

Hitachi Abb Power Grids Esoms