CVE-2021-27416: Cross-site scripting in Hitachi ABB Power Grids Ellipse EAM
An attacker could exploit this vulnerability in Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 by tricking a user to click on a link containing malicious code that would then be run by the web browser. This can result in the compromise of confidential information, or even the takeover of the user’s session.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-27416?
CVE-2021-27416 is a vulnerability that can be exploited in Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25.
How can an attacker exploit CVE-2021-27416?
An attacker can exploit CVE-2021-27416 by tricking a user into clicking on a link containing malicious code that will run in the web browser.
What is the severity of CVE-2021-27416?
The severity of CVE-2021-27416 is medium, with a severity value of 5.4.
What software versions are affected by CVE-2021-27416?
CVE-2021-27416 affects Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25.
How can I mitigate CVE-2021-27416?
To mitigate CVE-2021-27416, update Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) to version 9.0.26 or newer.