CVE-2021-35526: Storage of Sensitive Information Vulnerability in Hitachi ABB Power Grids System Data Manager – SDM600 Product

Published Sep 8, 2021
·
Updated

Backup file without encryption vulnerability is found in Hitachi ABB Power Grids System Data Manager – SDM600 allows attacker to gain access to sensitive information. This issue affects: Hitachi ABB Power Grids System Data Manager – SDM600 1.2 versions prior to FP2 HF6 (Build Nr. 1.2.14002.257).

Affected Software

3 affected componentsFixes available
Hitachi ABB Power Grids SDM600 FP2 HF6 (Build Nr. 1.2.14002.257)<1.2
1.2
Hitachiabb-powergrids Sdm600 Firmware>=1.2<1.2.14002.257
hitachienergy SDM600

Remediation

Information

The problem is remediated as of the following product version SDM600 version 1.2 FP2 HF6 (Build Nr. 1.2.14002.257). Hitachi ABB Power Grids recommends that customers apply the update at the earliest convenience. After successful upgrade it is recommended to move previously created vulnerable backups to secure place to avoid any nonauthorized access.

Event History

Sep 8, 2021
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
RemedyDescriptionSeverityWeakness

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2021-35526?

CVE-2021-35526 is a vulnerability found in Hitachi ABB Power Grids System Data Manager (SDM600) that allows an attacker to gain access to sensitive information by exploiting a backup file without encryption.

2

Which versions of Hitachi ABB Power Grids System Data Manager (SDM600) are affected?

Versions prior to FP2 HF6 (Build Nr. 1.2.14002.257) of Hitachi ABB Power Grids System Data Manager (SDM600) are affected by CVE-2021-35526.

3

What is the severity level of CVE-2021-35526?

CVE-2021-35526 has a severity level of 7.8, which is considered high.

4

How can an attacker exploit CVE-2021-35526?

An attacker can exploit CVE-2021-35526 by gaining access to sensitive information through an unencrypted backup file.

5

Are there any references or additional resources related to CVE-2021-35526?

Yes, you can find more information about CVE-2021-35526 in the references provided: [Reference 1](https://search.abb.com/library/Download.aspx?utm_campaign=&utm_content=2021.08_5051_Cybersecurity%20Advisory%3A&utm_medium=email&utm_source=Eloqua&DocumentID=9AKK107992A4700&LanguageCode=en&DocumentPartId=&Action=Launch&elqTrackId=ba79ef3d8aec4a4fad6c0cbe06d33d6c&elq=1bda419954724e908db108def16646a5&elqaid=3638&elqat=1&elqCampaignId=) [Reference 2](https://us-cert.cisa.gov/ics/advisories/icsa-21-250-02)

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203