ICSA-21-007-01
·
Published 2021-01-07
·
View on CISA ICS-CERT ↗
Hitachi ABB Power Grids FOX615 Multiservice-Multiplexer
CVSS 9.1
CRITICAL
Risk Summary
Successful exploitation of this vulnerability could allow an attacker remote access to the device without authentication.
CVEs (1)
Remediations
- Hitachi ABB Power Grids recommends users apply the following firmware: FOX61x R1: CESM1/CESM2: Update to Version cesne_r1h07_12.esw or newer
- Hitachi ABB Power Grids recommends users apply the following firmware: FOX61x R2: CESM1/CESM2: Update to Version cesne_r2d14_03.esw or newer
- For additional information and support please contact a product provider or Hitachi ABB Power Grids service organization.
- Hitachi ABB Power Grids recommends security practices and firewall configurations to help protect a process control network from attacks originating from outside the network. Such practices require process control systems be physically protected from direct access by unauthorized personnel, have no direct connections to the Internet, and are separated from other networks by a firewall system that has a minimal number of ports exposed. Other systems must be evaluated on case-by-case basis. Process control systems should not be used for Internet browsing, instant messaging, or receiving e-mails. Portable computers and removable storage media should be carefully scanned for viruses before they are connected to a control system.
Affected Vendors
Hitachi Energy
Affected Products (2)
Hitachi Energy
·
FOX61x R2 using CESM1/CESM2
< cesne_r2d14_03.esw
Hitachi Energy
·
FOX61x R1 using CESM1/CESM2
< cesne_r1h07_12.esw
Affected Sectors
Energy
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more