CVE-2021-35534
Last modified
CVE-2021-35534 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. Insufficient security control vulnerability in internal database access mechanism of Hitachi Energy Relion 670/650/SAM600-IO, Relion 650, GMS600, PWC600 allows attacker who successfully exploited this vulnerability, of which the product does not sufficiently restrict access to an internal database tables, could allow anybody with user credentials to bypass security controls that is enforced by the product. Consequently, exploitation may lead to unauthorized modifications on data/firmware, and/or to permanently disabling the product. EPSS estimates a 1.67% chance of exploitation in the next 30 days.
Description
Insufficient security control vulnerability in internal database access mechanism of Hitachi Energy Relion 670/650/SAM600-IO, Relion 650, GMS600, PWC600 allows attacker who successfully exploited this vulnerability, of which the product does not sufficiently restrict access to an internal database tables, could allow anybody with user credentials to bypass security controls that is enforced by the product. Consequently, exploitation may lead to unauthorized modifications on data/firmware, and/or to permanently disabling the product. This issue affects: Hitachi Energy Relion 670 Series 2.0 all revisions; 2.2.2 all revisions; 2.2.3 versions prior to 2.2.3.5. Hitachi Energy Relion 670/650 Series 2.1 all revisions. 2.2.0 all revisions; 2.2.4 all revisions; Hitachi Energy Relion 670/650/SAM600-IO 2.2.1 all revisions; 2.2.5 versions prior to 2.2.5.2. Hitachi Energy Relion 650 1.0 all revisions. 1.1 all revisions; 1.2 all revisions; 1.3 versions prior to 1.3.0.8; Hitachi Energy GMS600 1.3.0; 1.3.0.1; 1.2.0. Hitachi Energy PWC600 1.0.1 version 1.0.1.4 and prior versions; 1.1.0 version 1.1.0.1 and prior versions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hitachienergy | Gms600 Firmware | 1.2.0 |
| Hitachienergy | Gms600 Firmware | 1.3.0 |
| Hitachienergy | Gms600 Firmware | 1.3.1.0 |
| Hitachienergy | Relion 670 Firmware | All versions |
| Hitachienergy | Relion 670 Firmware | 2.0.0 |
| Hitachienergy | Relion 670 Firmware | 2.1.0 |
| Hitachienergy | Relion 670 Firmware | 2.2.0 |
| Hitachienergy | Relion 670 Firmware | 2.2.1 |
| Hitachienergy | Relion 670 Firmware | 2.2.2 |
| Hitachienergy | Relion 670 Firmware | 2.2.3 |
| Hitachienergy | Relion 670 Firmware | 2.2.4 |
| Hitachienergy | Relion 670 Firmware | 2.2.5 |
| Hitachienergy | Relion 650 Firmware | 1.0.0 |
| Hitachienergy | Relion 650 Firmware | 1.1.0 |
| Hitachienergy | Relion 650 Firmware | 1.2.0 |
| Hitachienergy | Relion 650 Firmware | 1.3.0 |
| Hitachienergy | Relion 650 Firmware | 2.1.0 |
| Hitachienergy | Relion 650 Firmware | 2.2.0 |
| Hitachienergy | Relion 650 Firmware | 2.2.1 |
| Hitachienergy | Relion 650 Firmware | 2.2.4 |
| Hitachienergy | Relion 650 Firmware | 2.2.5 |
| Hitachienergy | Relion Sam600-Io Firmware | 2.2.1 |
| Hitachienergy | Relion Sam600-Io Firmware | 2.2.5 |
| Hitachienergy | Pwc600 Firmware | 1.0.1.0 |
| Hitachienergy | Pwc600 Firmware | 1.0.1.1 |
| Hitachienergy | Pwc600 Firmware | 1.0.1.3 |
| Hitachienergy | Pwc600 Firmware | 1.0.1.4 |
| Hitachienergy | Pwc600 Firmware | 1.1.0.0 |
| Hitachienergy | Pwc600 Firmware | 1.1.0.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-35534?
How severe is CVE-2021-35534?
How do I fix CVE-2021-35534?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-35529Insufficiently Protected Credentials vulnerability in client…7.2
- CVE-2021-3553A Server-Side Request Forgery (SSRF) vulnerability in the EP…7.5
- CVE-2021-35530A vulnerability in the application authentication and author…6.7
- CVE-2021-35531Improper Input Validation vulnerability in a particular conf…6.7
- CVE-2021-35532A vulnerability exists in the file upload validation part of…6.7
- CVE-2021-35533Improper Input Validation vulnerability in the APDU parser i…7.5
- CVE-2021-35535Insecure Boot Image vulnerability in Hitachi Energy Relion R…8.1
- CVE-2021-35536Vulnerability in the Oracle Deal Management product of Oracl…8.1
- CVE-2021-35537Vulnerability in the MySQL Server product of Oracle MySQL (c…4.9
- CVE-2021-35538Vulnerability in the Oracle VM VirtualBox product of Oracle …7.8
- CVE-2021-35539Vulnerability in the Oracle Solaris product of Oracle System…6.5
- CVE-2021-3554Improper Access Control vulnerability in the patchesUpdate A…10
Are you affected by CVE-2021-35534?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
