← Back to home
ICSA-22-088-03  ·  Published 2022-03-29  ·  View on CISA ICS-CERT ↗

Hitachi Energy LinkOne WebView

CVSS 4.2 MEDIUM

Risk Summary

Successful exploitation of these vulnerabilities could allow an attacker to modify a victim 's system files or information, disclose application full path, disclose sensitive information to an unauthorized actor, and launch a common web attack.

Remediations

  • Hitachi Energy recommends applying the available security patch or updating LinkOne to v3.27. Contact Hitachi Energy for more information on applying the security patch or updating LinkOne to v3.27
  • Recommended security practices and firewall configurations can help protect the application from attacks that originate from outside the network. Such practices include physically protecting the application from direct access by unauthorized personnel, having no direct connections to the Internet. For the end-user of the application, it is recommended to use the latest browser when accessing the LinkOne application.
  • For more information, review Hitachi Energy's security advisory 8DBD000079
  • Additional recommendation is to follow the hardening guidelines published by The Center for Internet Security (CIS) to protect the host Operating System on which the LinkOne is hosted.
  • For additional information and support please contact your product provider or Hitachi Energy service.

Affected Vendors

Hitachi Energy

Affected Products (6)

Hitachi Energy · LinkOne WebView 3.25
Hitachi Energy · LinkOne WebView 3.23
Hitachi Energy · LinkOne WebView 3.22
Hitachi Energy · LinkOne WebView 3.24
Hitachi Energy · LinkOne WebView 3.26
Hitachi Energy · LinkOne WebView 3.2

Affected Sectors

Multiple Sectors

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more