← Back to home
ICSA-21-210-01  ·  Published 2021-07-29  ·  View on CISA ICS-CERT ↗

Hitachi ABB Power Grids eSOMS

CVSS 7.5 HIGH

Risk Summary

Successful exploitation of this vulnerability could allow access to user credentials that are stored by the browser.

CVEs (1)

Remediations

  • Hitachi ABB Power Grids recommends users update to Version 6.3.1 or later.
  • Hitachi ABB Power Grids also recommends implementing security best practices and firewall configurations, which help protect a process control network from attacks that originate from outside the network.
  • Ensuring critical applications and systems are physically protected from direct access by unauthorized personnel, have no direct connections to the Internet, and are separated from other networks by means of a firewall.
  • Firewalls should be configured to have the minimum number of ports exposed and open ports should be justified and documented.
  • Critical systems should not be used for Internet surfing, instant messaging, or receiving e-mails.
  • Portable computers and removable storage media should be carefully scanned for viruses before they are connected to a control system.
  • It is important to implement robust security awareness training to ensure users can identify common attacks or content such as phishing emails or malicious webpages.
  • For more information on this issue, see the Hitachi ABB Power Grid Security Advisory.

Affected Vendors

Hitachi Energy

Affected Products (1)

Hitachi Energy · eSOMS <= 6.3

Affected Sectors

Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more