CVE-2021-27414: User interface misrepresentation of critical information in Hitachi ABB Power Grids Ellipse EAM
An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 into visiting a malicious website posing as a login page for the Ellipse application and gather authentication credentials.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-27414?
CVE-2021-27414 refers to a vulnerability found in Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25.
How severe is CVE-2021-27414?
CVE-2021-27414 has a severity rating of 6.1, which is considered medium.
What is the description of CVE-2021-27414?
CVE-2021-27414 allows an attacker to trick users into visiting a malicious website posing as a login page for the Ellipse application and gather authentication credentials.
Which software versions are affected by CVE-2021-27414?
Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions up to and including 9.0.23 are affected by CVE-2021-27414.
How can I fix CVE-2021-27414?
To fix CVE-2021-27414, users are advised to upgrade to a version later than 9.0.23 of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM).