ICSA-21-341-02
·
Published 2021-12-07
·
View on CISA ICS-CERT ↗
Hitachi Energy XMC20 and FOX61x
CVSS 9.0
CRITICAL
Risk Summary
Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the Data Communication Network (DCN) routing configuration and cause a disruption to the Network Management (NMS) and Network Element (NE) communication.
CVEs (2)
Remediations
- XMC20: Upgrade to Version R15A
- FOX61x: Upgrade to Version R15A
- Please refer to the Hitachi Energy XMC20 advisory for more details on affected module information.
- Please refer to the Hitachi Energy FOX61x advisory for more details on affected module information.
- Physically protect process control systems from direct access by unauthorized personnel.
- Do not directly connect to the Internet.
- Separate from other networks by means of a firewall system that has a minimal number of ports exposed.
- Portable computers and removable storage media should be carefully scanned for viruses before they are connected to a control system.
- For additional information and access to updated firmware, please contact the Hitachi Energy service organization.
Affected Vendors
Hitachi Energy
Affected Products (2)
Hitachi Energy
·
XMC20
< R15A
Hitachi Energy
·
FOX61x
< R15A
Affected Sectors
Multiple Sectors
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more