← Back to home
ICSA-21-110-01  ·  Published 2021-04-20  ·  View on CISA ICS-CERT ↗

Hitachi ABB Power Grids Ellipse APM

CVSS 6.3 MEDIUM

Risk Summary

Successful exploitation of this vulnerability may allow an authenticated user or integrated application to inject malicious data into the application that can then be executed in a victim 's browser.

CVEs (1)

Remediations

  • Hitachi ABB Power Grids recommends users apply Ellipse APM Versions 5.3.0.2, 5.2.0.4, and 5.1.0.7 at the earliest convenience. Please see the advisory on the Hitachi ABB Power Grids website for more information.
  • Ensure the “Administrator” application role is only granted to fully trusted APM users who are trained not to import harmful data to APM (e.g., containing HTML or JavaScript).
  • Limit all “Import” role API credentials and integrations to only those providing safe data. Introduce filters in the source applications to ensure data safety.
  • Introduce a Web Application Firewall solution in front of the APM web interfaces with a capability of blocking XSS attack payloads in HTTP(S) requests, both plain REST (JSON/XML) as well as Excel files wrapped in REST (JSON).

Affected Vendors

Hitachi Energy

Affected Products (3)

Hitachi Energy · Ellipse APM <= 5.1.0.6
Hitachi Energy · Ellipse APM <= 5.2.0.3
Hitachi Energy · Ellipse APM <= 5.3.0.1

Affected Sectors

Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more