CVE-2021-35534
Summary
| CVE | CVE-2021-35534 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-18 17:15:00 UTC |
| Updated | 2023-04-19 15:32:00 UTC |
| Description | Insufficient security control vulnerability in internal database access mechanism of Hitachi Energy Relion 670/650/SAM600-IO, Relion 650, GMS600, PWC600 allows attacker who successfully exploited this vulnerability, of which the product does not sufficiently restrict access to an internal database tables, could allow anybody with user credentials to bypass security controls that is enforced by the product. Consequently, exploitation may lead to unauthorized modifications on data/firmware, and/or to permanently disabling the product. This issue affects: Hitachi Energy Relion 670 Series 2.0 all revisions; 2.2.2 all revisions; 2.2.3 versions prior to 2.2.3.5. Hitachi Energy Relion 670/650 Series 2.1 all revisions. 2.2.0 all revisions; 2.2.4 all revisions; Hitachi Energy Relion 670/650/SAM600-IO 2.2.1 all revisions; 2.2.5 versions prior to 2.2.5.2. Hitachi Energy Relion 650 1.0 all revisions. 1.1 all revisions; 1.2 all revisions; 1.3 versions prior to 1.3.0.8; Hitachi Energy GMS600 1.3.0; 1.3.0.1; 1.2.0. Hitachi Energy PWC600 1.0.1 version 1.0.1.4 and prior versions; 1.1.0 version 1.1.0.1 and prior versions. |
Risk And Classification
Problem Types: CWE-269
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Hitachi | Gms600 | - | All | All | All |
| Operating System | Hitachi | Gms600 Firmware | 1.2.0 | All | All | All |
| Operating System | Hitachi | Gms600 Firmware | 1.3.0 | All | All | All |
| Operating System | Hitachi | Gms600 Firmware | 1.3.1.0 | All | All | All |
| Hardware | Hitachi | Pwc600 | - | All | All | All |
| Operating System | Hitachi | Pwc600 Firmware | 1.0.1.0 | All | All | All |
| Operating System | Hitachi | Pwc600 Firmware | 1.0.1.1 | All | All | All |
| Operating System | Hitachi | Pwc600 Firmware | 1.0.1.3 | All | All | All |
| Operating System | Hitachi | Pwc600 Firmware | 1.0.1.4 | All | All | All |
| Operating System | Hitachi | Pwc600 Firmware | 1.1.0.0 | All | All | All |
| Operating System | Hitachi | Pwc600 Firmware | 1.1.0.1 | All | All | All |
| Hardware | Hitachi | Relion 650 | - | All | All | All |
| Operating System | Hitachi | Relion 650 Firmware | 1.0.0 | All | All | All |
| Operating System | Hitachi | Relion 650 Firmware | 1.1.0 | All | All | All |
| Operating System | Hitachi | Relion 650 Firmware | 1.2.0 | All | All | All |
| Operating System | Hitachi | Relion 650 Firmware | 1.3.0 | All | All | All |
| Operating System | Hitachi | Relion 650 Firmware | 2.1.0 | All | All | All |
| Operating System | Hitachi | Relion 650 Firmware | 2.2.0 | All | All | All |
| Operating System | Hitachi | Relion 650 Firmware | 2.2.1 | All | All | All |
| Operating System | Hitachi | Relion 650 Firmware | 2.2.4 | All | All | All |
| Operating System | Hitachi | Relion 650 Firmware | 2.2.5 | All | All | All |
| Hardware | Hitachi | Relion 670 | - | All | All | All |
| Operating System | Hitachi | Relion 670 Firmware | All | All | All | All |
| Operating System | Hitachi | Relion 670 Firmware | 2.0.0 | All | All | All |
| Operating System | Hitachi | Relion 670 Firmware | 2.1.0 | All | All | All |
| Operating System | Hitachi | Relion 670 Firmware | 2.2.0 | All | All | All |
| Operating System | Hitachi | Relion 670 Firmware | 2.2.1 | All | All | All |
| Operating System | Hitachi | Relion 670 Firmware | 2.2.2 | All | All | All |
| Operating System | Hitachi | Relion 670 Firmware | 2.2.3 | All | All | All |
| Operating System | Hitachi | Relion 670 Firmware | 2.2.4 | All | All | All |
| Operating System | Hitachi | Relion 670 Firmware | 2.2.5 | All | All | All |
| Hardware | Hitachi | Relion Sam600-io | - | All | All | All |
| Operating System | Hitachi | Relion Sam600-io Firmware | 2.2.1 | All | All | All |
| Operating System | Hitachi | Relion Sam600-io Firmware | 2.2.5 | All | All | All |
| Hardware | Hitachienergy | Gms600 | - | All | All | All |
| Operating System | Hitachienergy | Gms600 Firmware | 1.2.0 | All | All | All |
| Operating System | Hitachienergy | Gms600 Firmware | 1.3.0 | All | All | All |
| Operating System | Hitachienergy | Gms600 Firmware | 1.3.1.0 | All | All | All |
| Hardware | Hitachienergy | Pwc600 | - | All | All | All |
| Operating System | Hitachienergy | Pwc600 Firmware | 1.0.1.0 | All | All | All |
| Operating System | Hitachienergy | Pwc600 Firmware | 1.0.1.1 | All | All | All |
| Operating System | Hitachienergy | Pwc600 Firmware | 1.0.1.3 | All | All | All |
| Operating System | Hitachienergy | Pwc600 Firmware | 1.0.1.4 | All | All | All |
| Operating System | Hitachienergy | Pwc600 Firmware | 1.1.0.0 | All | All | All |
| Operating System | Hitachienergy | Pwc600 Firmware | 1.1.0.1 | All | All | All |
| Hardware | Hitachienergy | Relion 650 | - | All | All | All |
| Operating System | Hitachienergy | Relion 650 Firmware | 1.0.0 | All | All | All |
| Operating System | Hitachienergy | Relion 650 Firmware | 1.1.0 | All | All | All |
| Operating System | Hitachienergy | Relion 650 Firmware | 1.2.0 | All | All | All |
| Operating System | Hitachienergy | Relion 650 Firmware | 1.3.0 | All | All | All |
| Operating System | Hitachienergy | Relion 650 Firmware | 2.1.0 | All | All | All |
| Operating System | Hitachienergy | Relion 650 Firmware | 2.2.0 | All | All | All |
| Operating System | Hitachienergy | Relion 650 Firmware | 2.2.1 | All | All | All |
| Operating System | Hitachienergy | Relion 650 Firmware | 2.2.4 | All | All | All |
| Operating System | Hitachienergy | Relion 650 Firmware | 2.2.5 | All | All | All |
| Hardware | Hitachienergy | Relion 670 | - | All | All | All |
| Operating System | Hitachienergy | Relion 670 Firmware | All | All | All | All |
| Operating System | Hitachienergy | Relion 670 Firmware | 2.0.0 | All | All | All |
| Operating System | Hitachienergy | Relion 670 Firmware | 2.1.0 | All | All | All |
| Operating System | Hitachienergy | Relion 670 Firmware | 2.2.0 | All | All | All |
| Operating System | Hitachienergy | Relion 670 Firmware | 2.2.1 | All | All | All |
| Operating System | Hitachienergy | Relion 670 Firmware | 2.2.2 | All | All | All |
| Operating System | Hitachienergy | Relion 670 Firmware | 2.2.3 | All | All | All |
| Operating System | Hitachienergy | Relion 670 Firmware | 2.2.4 | All | All | All |
| Operating System | Hitachienergy | Relion 670 Firmware | 2.2.5 | All | All | All |
| Hardware | Hitachienergy | Relion Sam600-io | - | All | All | All |
| Operating System | Hitachienergy | Relion Sam600-io Firmware | 2.2.1 | All | All | All |
| Operating System | Hitachienergy | Relion Sam600-io Firmware | 2.2.5 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| search.abb.com/library/Download.aspx | CONFIRM | search.abb.com | |
| search.abb.com/library/Download.aspx | CONFIRM | search.abb.com | |
| search.abb.com/library/Download.aspx | CONFIRM | search.abb.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Hitachi Energy thanks the following for working with us to help protect customers: U.S. Department of Energy CyTRICS researcher Robert Erbes.
There are currently no legacy QID mappings associated with this CVE.