// For flags

CVE-2021-35528

Authentication Bypass Vulnerability Vulnerability in Retail Operations Product and Counterparty Settlement and Billing (CSB)

Severity Score

7.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Java Applet JAR file. A successful exploitation may lead to data extraction or modification of data inside the application. This issue affects: Hitachi Energy Retail Operations 5.7.3 and prior versions. Hitachi Energy Counterparty Settlement and Billing (CSB) 5.7.3 prior versions.

Una vulnerabilidad de control de acceso inapropiado en la autenticación y autorización de la aplicación de Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) permite a un atacante ejecutar un archivo JAR Java Applet firmado modificado. Una explotación con éxito puede conllevar a una extracción de datos o la modificación de datos dentro de la aplicación. Este problema afecta a: Hitachi Energy Retail Operations versiones 5.7.3 y anteriores. Hitachi Energy Counterparty Settlement and Billing (CSB) versiones 5.7.3 y anteriores

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Local
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-06-28 CVE Reserved
  • 2021-11-17 CVE Published
  • 2023-06-10 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-284: Improper Access Control
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hitachienergy
Search vendor "Hitachienergy"
Counterparty Settlements And Billing
Search vendor "Hitachienergy" for product "Counterparty Settlements And Billing"
<= 5.7.3
Search vendor "Hitachienergy" for product "Counterparty Settlements And Billing" and version " <= 5.7.3"
-
Affected
Hitachienergy
Search vendor "Hitachienergy"
Retail Operations
Search vendor "Hitachienergy" for product "Retail Operations"
<= 5.7.3
Search vendor "Hitachienergy" for product "Retail Operations" and version " <= 5.7.3"
-
Affected