CVE-2021-35532: Firmware upload verification bypass in TXpert Hub CoreTec 4
A vulnerability exists in the file upload validation part of Hitachi Energy TXpert Hub CoreTec 4 product. The vulnerability allows an attacker or malicious agent who manages to gain access to the system and obtain an account with sufficient privilege to upload a malicious firmware to the product. This issue affects: Hitachi Energy TXpert Hub CoreTec 4 version 2.0.0; 2.0.1; 2.1.0; 2.1.1; 2.1.2; 2.1.3; 2.2.0; 2.2.1.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-35532.
What is the severity of CVE-2021-35532?
The severity of CVE-2021-35532 is high with a CVSS score of 6.7.
How does the vulnerability affect Hitachi Energy TXpert Hub CoreTec 4 firmware?
The vulnerability affects versions 2.0.0 to 2.2.1 of Hitachi Energy TXpert Hub CoreTec 4 firmware.
What is the risk of the vulnerability?
The vulnerability allows an attacker with sufficient privilege to upload a malicious firmware to the product, posing a significant risk to the system.
Is there a fix available for CVE-2021-35532?
It is recommended to update to a patched version of Hitachi Energy TXpert Hub CoreTec 4 firmware to mitigate the vulnerability.