CRITICAL · 9.0

CVE-2021-40333

Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access to the Data Communication Network (DCN) routing configuration. This issue affect...

Vulnerability Description

Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access to the Data Communication Network (DCN) routing configuration. This issue affects: Hitachi Energy FOX61x versions prior to R15A. Hitachi Energy XCM20 versions prior to R15A.

CVSS Score

9.0

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
LOW
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
HitachienergyFox615 Firmware< r15a
HitachienergyFox615-
HitachienergyXcm20 Firmware< r15a
HitachienergyXcm20-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-40333?

CVE-2021-40333 is a vulnerability with a CVSS score of 9.0 (CRITICAL). Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access to the Data Communication Network (DCN) routing configuration. This issue affect...

How severe is CVE-2021-40333?

CVE-2021-40333 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-40333?

Check the references section above for vendor advisories and patch information. Affected products include: Hitachienergy Fox615 Firmware, Hitachienergy Fox615, Hitachienergy Xcm20 Firmware, Hitachienergy Xcm20.