Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-40337


Cross-site Scripting (XSS) vulnerability in Hitachi Energy LinkOne allows an attacker that manages to exploit the vulnerability can take advantage to exploit multiple web attacks and stole sensitive information. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23; 3.24; 3.25; 3.26.


Published

2022-01-25T20:15:08.403

Last Modified

2024-11-21T06:23:53.587

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.2 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

6.8

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-79
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hitachi linkone 3.20 Yes
Application hitachi linkone 3.22 Yes
Application hitachi linkone 3.23 Yes
Application hitachi linkone 3.24 Yes
Application hitachi linkone 3.25 Yes
Application hitachi linkone 3.26 Yes

References