Code Injection in Hitachi Energy products - CVE-2021-35535
Published: December 3, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists in the early boot process of the product in which there is a tiny time gap where a previous version of VxWorks is loaded prior to booting up the complete application firmware. A remote attacker can execute arbitrary code on the target device before the operating system is loaded.
Affected software
Relion 650 series
Relion SAM600-IO
How to mitigate CVE-2021-35535
Relion 650 series - update to 2.2.5
Relion SAM600-IO - update to 2.2.5