CVE-2021-35531: Remote Code Execution in TXpert Hub CoreTec 4
Improper Input Validation vulnerability in a particular configuration setting field of Hitachi Energy TXpert Hub CoreTec 4 product, allows an attacker with access to an authorized user with ADMIN or ENGINEER role rights to inject an OS command that is executed by the system. This issue affects: Hitachi Energy TXpert Hub CoreTec 4 version 2.0.0; 2.0.1; 2.1.0; 2.1.1; 2.1.2; 2.1.3; 2.2.0; 2.2.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-35531?
CVE-2021-35531 is an Improper Input Validation vulnerability in a particular configuration setting field of Hitachi Energy TXpert Hub CoreTec 4 product.
What role rights are required to exploit CVE-2021-35531?
An attacker with access to an authorized user with ADMIN or ENGINEER role rights can exploit CVE-2021-35531.
Which versions of Hitachi Energy TXpert Hub CoreTec 4 firmware are affected by CVE-2021-35531?
CVE-2021-35531 affects versions 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0, and 2.2.1 of Hitachi Energy TXpert Hub CoreTec 4 firmware.
What is the severity of CVE-2021-35531?
CVE-2021-35531 has a severity value of 6.7 (high).
How can I fix CVE-2021-35531?
To fix CVE-2021-35531, it is recommended to apply the necessary patches or updates provided by Hitachi Energy.