SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-40339

Configuration vulnerability in Hitachi Energy LinkOne application due to the lack of HTTP Headers, allows an attacker that manages to exploit this vulnerability to retrieve sensitive information.

HIGH 7.5EPSS 0.73%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Configuration vulnerability in Hitachi Energy LinkOne application due to the lack of HTTP Headers, allows an attacker that manages to exploit this vulnerability to retrieve sensitive information. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23; 3.24; 3.25; 3.26.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.73% probability · 52th percentile
CISA KEV
Not listed
Affected
hitachi/linkone
Source
cybersecurity@hitachienergy.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.