cve/2021/CVE-2021-35528.md

19 lines
1.2 KiB
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2021-35528](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-35528)
![](https://img.shields.io/static/v1?label=Product&message=Counterparty%20Settlement%20and%20Billing%20(CSB)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Retail%20Operations&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=5.7.3%3C%205.7.3.1%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-284%20Improper%20Access%20Control&color=brighgreen)
### Description
Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Java Applet JAR file. A successful exploitation may lead to data extraction or modification of data inside the application. This issue affects: Hitachi Energy Retail Operations 5.7.3 and prior versions. Hitachi Energy Counterparty Settlement and Billing (CSB) 5.7.3 prior versions.
### POC
#### Reference
- https://search.abb.com/library/Download.aspx?DocumentID=8DBD000068&LanguageCode=en&DocumentPartId=&Action=Launch
#### Github
No PoCs found on GitHub currently.