User authentication bypass in TXpert Hub CoreTec 4
CVE-2021-35530

6MEDIUM

Key Information:

Vendor
Hitachi
Vendor
CVE Published:
10 May 2022

Summary

A vulnerability in the application authentication and authorization mechanism in Hitachi Energy's TXpert Hub CoreTec 4, that depends on a token validation of the session identifier, allows an unauthorized modified message to be executed in the server enabling an unauthorized actor to change an existing user password, and further gain authorized access into the system via login mechanism. This issue affects: Hitachi Energy TXpert Hub CoreTec 4 version 2.0.0 2.1.0; 2.1.0; 2.1.1; 2.1.2; 2.1.3; 2.2.0; 2.2.1.

Affected Version(s)

TXpert Hub CoreTec 4 version 2.0.0

TXpert Hub CoreTec 4 version 2.0.1

TXpert Hub CoreTec 4 version 2.1.0

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.