#VU67053 Download of code without integrity check in TXpert Hub CoreTec 4 - CVE-2021-35532
Published: September 7, 2022
TXpert Hub CoreTec 4
Hitachi Energy
Description
The vulnerability allows a local user to compromise the affected system
The vulnerability exists due to software does not perform software integrity check when downloading updates within the file upload validation component. A local administrator can gain access to the system and obtain an account with sufficient privilege to then upload a malicious firmware to the product.