← Back to home
ICSA-21-341-02  ·  Published 2021-12-07  ·  View on CISA ICS-CERT ↗

Hitachi Energy XMC20 and FOX61x

CVSS 9.0 CRITICAL

Risk Summary

Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the Data Communication Network (DCN) routing configuration and cause a disruption to the Network Management (NMS) and Network Element (NE) communication.

Remediations

  • XMC20: Upgrade to Version R15A
  • FOX61x: Upgrade to Version R15A
  • Please refer to the Hitachi Energy XMC20 advisory for more details on affected module information.
  • Please refer to the Hitachi Energy FOX61x advisory for more details on affected module information.
  • Physically protect process control systems from direct access by unauthorized personnel.
  • Do not directly connect to the Internet.
  • Separate from other networks by means of a firewall system that has a minimal number of ports exposed.
  • Portable computers and removable storage media should be carefully scanned for viruses before they are connected to a control system.
  • For additional information and access to updated firmware, please contact the Hitachi Energy service organization.

Affected Vendors

Hitachi Energy

Affected Products (2)

Hitachi Energy · XMC20 < R15A
Hitachi Energy · FOX61x < R15A

Affected Sectors

Multiple Sectors

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more