Vulnerability Description
A vulnerability exists in the file upload validation part of Hitachi Energy TXpert Hub CoreTec 4 product. The vulnerability allows an attacker or malicious agent who manages to gain access to the system and obtain an account with sufficient privilege to upload a malicious firmware to the product. This issue affects: Hitachi Energy TXpert Hub CoreTec 4 version 2.0.0; 2.0.1; 2.1.0; 2.1.1; 2.1.2; 2.1.3; 2.2.0; 2.2.1.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hitachienergy | Txpert Hub Coretec 4 Firmware | 2.0.0 |
| Hitachienergy | Txpert Hub Coretec 4 | - |
Related Weaknesses (CWE)
References
- https://search.abb.com/library/Download.aspx?DocumentID=8DBD000080&LanguageCode=Vendor Advisory
- https://search.abb.com/library/Download.aspx?DocumentID=8DBD000080&LanguageCode=Vendor Advisory
FAQ
What is CVE-2021-35532?
CVE-2021-35532 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A vulnerability exists in the file upload validation part of Hitachi Energy TXpert Hub CoreTec 4 product. The vulnerability allows an attacker or malicious agent who manages to gain access to the syst...
How severe is CVE-2021-35532?
CVE-2021-35532 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-35532?
Check the references section above for vendor advisories and patch information. Affected products include: Hitachienergy Txpert Hub Coretec 4 Firmware, Hitachienergy Txpert Hub Coretec 4.