Lucene search

K
cvelistHitachi EnergyCVELIST:CVE-2021-35528
HistoryNov 17, 2021 - 5:55 p.m.

CVE-2021-35528 Authentication Bypass Vulnerability Vulnerability in Retail Operations Product and Counterparty Settlement and Billing (CSB)

2021-11-1717:55:45
CWE-284
Hitachi Energy
www.cve.org
2
cve-2021-35528
authentication bypass
vulnerability
retail operations
counterparty settlement
billing
hitachi energy
access control
data modification

CVSS3

7.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N

EPSS

0

Percentile

12.6%

Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Java Applet JAR file. A successful exploitation may lead to data extraction or modification of data inside the application. This issue affects: Hitachi Energy Retail Operations 5.7.3 and prior versions. Hitachi Energy Counterparty Settlement and Billing (CSB) 5.7.3 prior versions.

CNA Affected

[
  {
    "product": "Retail Operations",
    "vendor": "Hitachi Energy",
    "versions": [
      {
        "lessThan": "5.7.3.1",
        "status": "affected",
        "version": "5.7.3",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "Counterparty Settlement and Billing (CSB)",
    "vendor": "Hitachi Energy",
    "versions": [
      {
        "lessThan": "5.7.3.1",
        "status": "affected",
        "version": "5.7.3",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N

EPSS

0

Percentile

12.6%

Related for CVELIST:CVE-2021-35528