### [CVE-2021-27414](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27414) ![](https://img.shields.io/static/v1?label=Product&message=Ellipse%20Enterprise%20Asset%20Management%20(EAM)&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=%3C%3D%209.0.25%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-451%20User%20Interface%20(UI)%20Misrepresentation%20of%20Critical%20Information&color=brighgreen) ### Description An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 into visiting a malicious website posing as a login page for the Ellipse application and gather authentication credentials. ### POC #### Reference - https://search.abb.com/library/Download.aspx?DocumentID=9AKK107991A7777&LanguageCode=en&DocumentPartId=&Action=Launch #### Github No PoCs found on GitHub currently.