{"containers":{"cna":{"affected":[{"product":"LinkOne","vendor":"Hitachi Energy","versions":[{"status":"affected","version":"3.20"},{"status":"affected","version":"3.22"},{"status":"affected","version":"3.23"},{"status":"affected","version":"3.24"},{"status":"affected","version":"3.25"},{"status":"affected","version":"3.26"}]}],"credits":[{"lang":"en","value":"Hitachi Energy thanks the following for working with us to help protect our customers:  Compañía Minera Doña Inés de Collahuasi SCM."}],"datePublic":"2021-12-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site Scripting (XSS) vulnerability in Hitachi Energy LinkOne allows an attacker that manages to exploit the vulnerability can take advantage to exploit multiple web attacks and stole sensitive information. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23; 3.24; 3.25; 3.26."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.2,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-79","description":"CWE-79 Cross-site Scripting (XSS)","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2022-01-25T19:11:15.000Z","orgId":"e383dce4-0c27-4495-91c4-0db157728d17","shortName":"Hitachi Energy"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://search.abb.com/library/Download.aspx?DocumentID=8DBD000079&LanguageCode=en&DocumentPartId=&Action=Launch"}],"solutions":[{"lang":"en","value":"For each version, apply the available patch or update to version 3.27."}],"source":{"discovery":"USER"},"title":"OWASP Related Vulnerabilities in Hitachi  Energy’s LinkOne Product","x_generator":{"engine":"Vulnogram 0.0.9"},"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cybersecurity@hitachienergy.com","DATE_PUBLIC":"2021-12-23T17:00:00.000Z","ID":"CVE-2021-40337","STATE":"PUBLIC","TITLE":"OWASP Related Vulnerabilities in Hitachi  Energy’s LinkOne Product"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"LinkOne","version":{"version_data":[{"version_affected":"=","version_name":"3.20","version_value":"3.20"},{"version_affected":"=","version_name":"3.22","version_value":"3.22"},{"version_affected":"=","version_name":"3.23","version_value":"3.23"},{"version_affected":"=","version_name":"3.24","version_value":"3.24"},{"version_affected":"=","version_name":"3.25","version_value":"3.25"},{"version_affected":"=","version_name":"3.26","version_value":"3.26"}]}}]},"vendor_name":"Hitachi Energy"}]}},"credit":[{"lang":"eng","value":"Hitachi Energy thanks the following for working with us to help protect our customers:  Compañía Minera Doña Inés de Collahuasi SCM."}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site Scripting (XSS) vulnerability in Hitachi Energy LinkOne allows an attacker that manages to exploit the vulnerability can take advantage to exploit multiple web attacks and stole sensitive information. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23; 3.24; 3.25; 3.26."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.2,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-79 Cross-site Scripting (XSS)"}]}]},"references":{"reference_data":[{"name":"https://search.abb.com/library/Download.aspx?DocumentID=8DBD000079&LanguageCode=en&DocumentPartId=&Action=Launch","refsource":"CONFIRM","url":"https://search.abb.com/library/Download.aspx?DocumentID=8DBD000079&LanguageCode=en&DocumentPartId=&Action=Launch"}]},"solution":[{"lang":"en","value":"For each version, apply the available patch or update to version 3.27."}],"source":{"discovery":"USER"}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-04T02:27:31.930Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://search.abb.com/library/Download.aspx?DocumentID=8DBD000079&LanguageCode=en&DocumentPartId=&Action=Launch"}]}]},"cveMetadata":{"assignerOrgId":"e383dce4-0c27-4495-91c4-0db157728d17","assignerShortName":"Hitachi Energy","cveId":"CVE-2021-40337","datePublished":"2022-01-25T19:11:15.088Z","dateReserved":"2021-08-31T00:00:00.000Z","dateUpdated":"2024-09-16T22:08:41.501Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}