PT-2022-11219 · Hitachi Energy · Hitachi Energy Linkone

Published

2022-01-28

·

Updated

2022-02-03

·

CVE-2021-40340

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Hitachi Energy LinkOne versions 3.20 through 3.26
Description The issue is related to an Information Exposure vulnerability in the Hitachi Energy LinkOne application. This vulnerability is caused by a misconfiguration in the ASP server, which exposes server and ASP.net information. An attacker who exploits this vulnerability can use the exposed information for reconnaissance to plan further exploitation.
Recommendations For Hitachi Energy LinkOne versions 3.20 through 3.26, update to a version that fixes the misconfiguration in the ASP server to prevent information exposure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-40340

Affected Products

Hitachi Energy Linkone