Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-35535


Insecure Boot Image vulnerability in Hitachi Energy Relion Relion 670/650/SAM600-IO series allows an attacker who manages to get access to the front network port and to cause a reboot sequences of the device may exploit the vulnerability, where there is a tiny time gap during the booting process where an older version of VxWorks is loaded prior to application firmware booting, could exploit the vulnerability in the older version of VxWorks and cause a denial-of-service on the product. This issue affects: Hitachi Energy Relion 670 Series 2.2.2 all revisions; 2.2.3 versions prior to 2.2.3.3. Hitachi Energy Relion 670/650 Series 2.2.0 all revisions; 2.2.4 all revisions. Hitachi Energy Relion 670/650/SAM600-IO 2.2.1 all revisions.


Published

2021-11-18T16:15:08.450

Last Modified

2024-11-21T06:12:27.977

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-1188
  • Type: Primary
    CWE-1188

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System hitachienergy relion_670_firmware ≤ 2.2.3.3 Yes
Operating System hitachienergy relion_670_firmware 2.2.0 Yes
Operating System hitachienergy relion_670_firmware 2.2.1 Yes
Operating System hitachienergy relion_670_firmware 2.2.2 Yes
Operating System hitachienergy relion_670_firmware 2.2.4 Yes
Hardware hitachienergy relion_670 - No
Operating System hitachienergy relion_650_firmware 2.2.0 Yes
Operating System hitachienergy relion_650_firmware 2.2.1 Yes
Operating System hitachienergy relion_650_firmware 2.2.4 Yes
Hardware hitachienergy relion_650 - No
Operating System hitachienergy relion_sam600-io_firmware 2.2.1 Yes
Hardware hitachienergy relion_sam600-io - No

References