First published: Tue Nov 23 2021(Updated: )
Missing Handler vulnerability in the proprietary management protocol (port TCP 5558) of Hitachi Energy FOX61x, XCM20 allows an attacker that exploits the vulnerability by activating SSH on port TCP 5558 to cause disruption to the NMS and NE communication. This issue affects: Hitachi Energy FOX61x versions prior to R15A. Hitachi Energy XCM20 versions prior to R15A.
Credit: cybersecurity@hitachienergy.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachienergy Fox615 Firmware | <r15a | |
Hitachienergy Fox615 | ||
Hitachienergy Xcm20 Firmware | <r15a | |
Hitachienergy Xcm20 |
Fixed in FOX61x R15A or XMC20 R15A
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID of this vulnerability is CVE-2021-40334.
The severity rating of CVE-2021-40334 is 7.5 (high).
The Hitachi Energy FOX61x (firmware up to exclusive version r15a) and Hitachi Energy XCM20 (firmware up to exclusive version r15a) are affected by CVE-2021-40334.
An attacker can exploit CVE-2021-40334 by activating SSH on port TCP 5558 and causing disruption to the NMS and NE communication.
Yes, you can find references for CVE-2021-40334 at the following links: 1. [Reference 1](https://search.abb.com/library/Download.aspx?DocumentID=8DBD000062&LanguageCode=en&DocumentPartId=&Action=Launch) 2. [Reference 2](https://search.abb.com/library/Download.aspx?DocumentID=8DBD000069&LanguageCode=en&DocumentPartId=&Action=Launch)