PT-2022-10466 · Hitachi Energy · Txpert Hub Coretec 4

Published

2022-06-07

·

Updated

2023-06-26

·

CVE-2021-35530

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Hitachi Energy TXpert Hub CoreTec 4 versions 2.0.0 through 2.2.1
Description A vulnerability in the application authentication and authorization mechanism in Hitachi Energy's TXpert Hub CoreTec 4, that depends on a token validation of the session identifier, allows an unauthorized modified message to be executed in the server enabling an unauthorized actor to change an existing user password, and further gain authorized access into the system via login mechanism.
Recommendations For versions 2.0.0 through 2.2.1, consider disabling the token validation of the session identifier until a patch is available. Restrict access to the login mechanism to minimize the risk of exploitation. Avoid using the login mechanism with existing user passwords until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2021-35530

Affected Products

Txpert Hub Coretec 4