Vulnerabilities > Hitachi

DATE CVE VULNERABILITY TITLE RISK
2022-01-28 CVE-2021-40338 Information Exposure Through an Error Message vulnerability in Hitachi Linkone
Hitachi Energy LinkOne product, has a vulnerability due to a web server misconfiguration, that enables debug mode and reveals the full path of the filesystem directory when an attacker generates errors during a query operation.
network
low complexity
hitachi CWE-209
5.0
2022-01-28 CVE-2021-40339 Unspecified vulnerability in Hitachi Linkone
Configuration vulnerability in Hitachi Energy LinkOne application due to the lack of HTTP Headers, allows an attacker that manages to exploit this vulnerability to retrieve sensitive information.
network
low complexity
hitachi
5.0
2022-01-28 CVE-2021-40340 Information Exposure vulnerability in Hitachi Linkone
Information Exposure vulnerability in Hitachi Energy LinkOne application, due to a misconfiguration in the ASP server exposes server and ASP.net information, an attacker that manages to exploit this vulnerability can use the exposed information as a reconnaissance for further exploitation.
network
low complexity
hitachi CWE-200
5.0
2022-01-25 CVE-2021-40337 Cross-site Scripting vulnerability in Hitachi Linkone
Cross-site Scripting (XSS) vulnerability in Hitachi Energy LinkOne allows an attacker that manages to exploit the vulnerability can take advantage to exploit multiple web attacks and stole sensitive information.
network
hitachi CWE-79
3.5
2021-11-18 CVE-2021-35534 Incorrect Authorization vulnerability in Hitachi products
Insufficient security control vulnerability in internal database access mechanism of Hitachi Energy Relion 670/650/SAM600-IO, Relion 650, GMS600, PWC600 allows attacker who successfully exploited this vulnerability, of which the product does not sufficiently restrict access to an internal database tables, could allow anybody with user credentials to bypass security controls that is enforced by the product.
network
low complexity
hitachi CWE-863
critical
9.0
2021-11-18 CVE-2021-35535 Insecure Default Initialization of Resource vulnerability in Hitachi products
Insecure Boot Image vulnerability in Hitachi Energy Relion Relion 670/650/SAM600-IO series allows an attacker who manages to get access to the front network port and to cause a reboot sequences of the device may exploit the vulnerability, where there is a tiny time gap during the booting process where an older version of VxWorks is loaded prior to application firmware booting, could exploit the vulnerability in the older version of VxWorks and cause a denial-of-service on the product.
network
hitachi CWE-1188
6.8
2021-11-08 CVE-2021-31599 Unrestricted Upload of File with Dangerous Type vulnerability in Hitachi products
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x.
network
low complexity
hitachi CWE-434
6.5
2021-11-08 CVE-2021-31600 Files or Directories Accessible to External Parties vulnerability in Hitachi products
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x.
network
low complexity
hitachi CWE-552
4.0
2021-11-08 CVE-2021-31601 Unspecified vulnerability in Hitachi products
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x.
network
low complexity
hitachi
4.0
2021-11-08 CVE-2021-31602 Improper Authentication vulnerability in Hitachi products
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x.
network
low complexity
hitachi CWE-287
5.0