PT-2022-5004 · Hitachi Energy · Hitachi Energy Msm

Published

2022-07-25

·

Updated

2023-06-26

·

CVE-2021-40336

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Hitachi Energy MSM versions V2.2 and prior
Description A vulnerability exists in the HTTP web interface where it does not validate data in an HTTP header, leading to a possible HTTP response splitting. This could allow an attacker to channel harmful code into the user's web browser, potentially stealing session cookies. An attacker could trick a user into downloading malicious software by sending a forged link to the MSM web interface via email.
Recommendations For Hitachi Energy MSM versions V2.2 and prior, update to a version that fixes this issue to prevent HTTP response splitting and potential code injection. As a temporary workaround, consider restricting access to the HTTP web interface to minimize the risk of exploitation. Avoid clicking on links from untrusted sources, especially those that lead to the MSM web interface, to reduce the risk of downloading malicious software.

Fix

CSRF

Special Elements Injection

Weakness Enumeration

Related Identifiers

BDU:2022-06217
CVE-2021-40336

Affected Products

Hitachi Energy Msm