CVE-2021-35535
Insufficient Security Control Vulnerability
Description
Hitachi Energy is aware of a report from U.S. Department of Energy CyTRICS researcher of a vulnerability in the Relion 670/650/SAM600-IO series versions listed below. Recommended action for each affected version is listed in the Recommended Immediate Actions Section. An attacker who manages to get access to the front network port and to cause a reboot sequences of the device may exploit the vulnerability, where there is a tiny time gap during the booting process where an older version of VxWorks is loaded prior to application firmware booting, could exploit the vulnerability in the older version of VxWorks and cause a denial-of-service on the product.
CVSS Vector Breakdown
AV:LAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
References
Timeline
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2021-35535 and every CVE in our database. Create a free account — no credit card required.
Create Free Account