ICSA-21-210-01
·
Published 2021-07-29
·
View on CISA ICS-CERT ↗
Hitachi ABB Power Grids eSOMS
CVSS 7.5
HIGH
Risk Summary
Successful exploitation of this vulnerability could allow access to user credentials that are stored by the browser.
CVEs (1)
Remediations
- Hitachi ABB Power Grids recommends users update to Version 6.3.1 or later.
- Hitachi ABB Power Grids also recommends implementing security best practices and firewall configurations, which help protect a process control network from attacks that originate from outside the network.
- Ensuring critical applications and systems are physically protected from direct access by unauthorized personnel, have no direct connections to the Internet, and are separated from other networks by means of a firewall.
- Firewalls should be configured to have the minimum number of ports exposed and open ports should be justified and documented.
- Critical systems should not be used for Internet surfing, instant messaging, or receiving e-mails.
- Portable computers and removable storage media should be carefully scanned for viruses before they are connected to a control system.
- It is important to implement robust security awareness training to ensure users can identify common attacks or content such as phishing emails or malicious webpages.
- For more information on this issue, see the Hitachi ABB Power Grid Security Advisory.
Affected Vendors
Hitachi Energy
Affected Products (1)
Hitachi Energy
·
eSOMS
<= 6.3
Affected Sectors
Energy
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more