CVE-2021-35526: Storage of Sensitive Information Vulnerability in Hitachi ABB Power Grids System Data Manager – SDM600 Product
Backup file without encryption vulnerability is found in Hitachi ABB Power Grids System Data Manager – SDM600 allows attacker to gain access to sensitive information. This issue affects: Hitachi ABB Power Grids System Data Manager – SDM600 1.2 versions prior to FP2 HF6 (Build Nr. 1.2.14002.257).
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-35526?
CVE-2021-35526 is a vulnerability found in Hitachi ABB Power Grids System Data Manager (SDM600) that allows an attacker to gain access to sensitive information by exploiting a backup file without encryption.
Which versions of Hitachi ABB Power Grids System Data Manager (SDM600) are affected?
Versions prior to FP2 HF6 (Build Nr. 1.2.14002.257) of Hitachi ABB Power Grids System Data Manager (SDM600) are affected by CVE-2021-35526.
What is the severity level of CVE-2021-35526?
CVE-2021-35526 has a severity level of 7.8, which is considered high.
How can an attacker exploit CVE-2021-35526?
An attacker can exploit CVE-2021-35526 by gaining access to sensitive information through an unencrypted backup file.
Are there any references or additional resources related to CVE-2021-35526?
Yes, you can find more information about CVE-2021-35526 in the references provided: [Reference 1](https://search.abb.com/library/Download.aspx?utm_campaign=&utm_content=2021.08_5051_Cybersecurity%20Advisory%3A&utm_medium=email&utm_source=Eloqua&DocumentID=9AKK107992A4700&LanguageCode=en&DocumentPartId=&Action=Launch&elqTrackId=ba79ef3d8aec4a4fad6c0cbe06d33d6c&elq=1bda419954724e908db108def16646a5&elqaid=3638&elqat=1&elqCampaignId=) [Reference 2](https://us-cert.cisa.gov/ics/advisories/icsa-21-250-02)