Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-40340


Information Exposure vulnerability in Hitachi Energy LinkOne application, due to a misconfiguration in the ASP server exposes server and ASP.net information, an attacker that manages to exploit this vulnerability can use the exposed information as a reconnaissance for further exploitation. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23; 3.24; 3.25; 3.26.


Published

2022-01-28T20:15:11.307

Last Modified

2024-11-21T06:23:54.010

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.7 (LOW)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hitachi linkone 3.20 Yes
Application hitachi linkone 3.22 Yes
Application hitachi linkone 3.23 Yes
Application hitachi linkone 3.24 Yes
Application hitachi linkone 3.25 Yes
Application hitachi linkone 3.26 Yes

References