CVE-2021-27414
User interface misrepresentation of critical information in Hitachi ABB Power Grids Ellipse EAM
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.5EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
11 mar 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 into visiting a malicious website posing as a login page for the Ellipse application and gather authentication credentials.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Productos afectados
Hitachi ABB Power Grids · Ellipse Enterprise Asset Management (EAM)¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →