PT-2021-20957 · Hitachi Energy · Pwc600+5

Published

2021-11-18

·

Updated

2023-04-19

·

CVE-2021-35534

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Hitachi Energy Relion 670 Series versions 2.0 through 2.2.3.4 Hitachi Energy Relion 670 Series version 2.2.4 Hitachi Energy Relion 670/650 Series versions 2.1 through 2.2.0 Hitachi Energy Relion 670/650 Series version 2.2.4 Hitachi Energy Relion 670/650/SAM600-IO versions 2.2.1 through 2.2.4.1 Hitachi Energy Relion 670/650/SAM600-IO versions 2.2.5 through 2.2.5.1 Hitachi Energy Relion 650 versions 1.0 through 1.3.0.7 Hitachi Energy GMS600 versions 1.2.0 through 1.3.0.1 Hitachi Energy PWC600 versions 1.0.1 through 1.0.1.3 Hitachi Energy PWC600 versions 1.1.0 through 1.1.0.0
Description: The vulnerability is related to an insufficient security control in the internal database access mechanism, allowing an attacker with user credentials to bypass security controls and potentially modify data or firmware, or permanently disable the product.
Recommendations: For Hitachi Energy Relion 670 Series versions 2.0 through 2.2.3.4, update to version 2.2.3.5 or later. For Hitachi Energy Relion 670 Series version 2.2.4, update to a version later than 2.2.4. For Hitachi Energy Relion 670/650 Series versions 2.1 through 2.2.0, update to a version later than 2.2.0. For Hitachi Energy Relion 670/650 Series version 2.2.4, update to a version later than 2.2.4. For Hitachi Energy Relion 670/650/SAM600-IO versions 2.2.1 through 2.2.4.1, update to version 2.2.5.2 or later. For Hitachi Energy Relion 650 versions 1.0 through 1.3.0.7, update to version 1.3.0.8 or later. For Hitachi Energy GMS600 versions 1.2.0 through 1.3.0.1, update to a version later than 1.3.0.1. For Hitachi Energy PWC600 versions 1.0.1 through 1.0.1.3, update to a version later than 1.0.1.3. For Hitachi Energy PWC600 versions 1.1.0 through 1.1.0.0, update to a version later than 1.1.0.0.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2021-35534

Affected Products

Gms600
Pwc600
Relion 650
Relion 670 Series
Relion 670/650 Series
Relion 670/650/Sam600-Io