CVE-2021-35527
published 2021-07-14CVE-2021-35527: Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids eSOMS allows attacker to gain access to user credentials…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.02%
59.4th percentile
Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids eSOMS allows attacker to gain access to user credentials that are stored by the browser. This issue affects: Hitachi ABB Power Grids eSOMS version 6.3 and prior versions.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ghost | sqlite3 | >= 0 < 3.22.0-1ubuntu0.6 | 3.22.0-1ubuntu0.6 |
| ghost | sqlite3 | >= 0 < 3.31.1-4ubuntu0.4 | 3.31.1-4ubuntu0.4 |
| hitachi_abb_power_grids | esoms | unspecified – 6.3 | — |
| hitachienergy | esoms | < 6.3.1 | 6.3.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
sqlite3 vulnerabilities
osv·2022-09-15·CVSS 7.5
CVE-2020-35525 sqlite3 vulnerabilities
sqlite3 vulnerabilities
It was discovered that SQLite incorrectly handled INTERSEC query
processing. An attacker could use this issue to cause SQLite to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2020-35525)
It was discovered that SQLite incorrectly handled ALTER TABLE for views
that have a nested FROM clause. An attacker could use this issue to cause
SQLite to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue was only addressed in Ubuntu 20.04 LTS.
(CVE-2020-35527)
It was discovered that SQLite incorrectly handled embedded null characters
when tokenizing certain unicode strings. This issue could result in
incorrect results. This issue only affected Ubuntu 20.04 LTS.
(CVE-2021-20223)
GHSA
GHSA-r627-fmvr-78q5: Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids eSOMS allows attacker to gain access to user cred
ghsa_unreviewed·2022-05-24
CVE-2021-35527 [HIGH] CWE-200 GHSA-r627-fmvr-78q5: Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids eSOMS allows attacker to gain access to user cred
Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids eSOMS allows attacker to gain access to user credentials that are stored by the browser. This issue affects: Hitachi ABB Power Grids eSOMS version 6.3 and prior versions.
CISA ICS
Hitachi ABB Power Grids eSOMS
cisa_ics·2021-07-29·CVSS 7.5
[HIGH] Hitachi ABB Power Grids eSOMS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi ABB Power Grids eSOMS
Last RevisedJuly 29, 2021
Alert CodeICSA-21-210-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Low attack complexity
- Vendor: Hitachi ABB Power Grids
- Equipment: eSOMS
- Vulnerability: Insufficiently Protected Credentials
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow access to user credentials that are stored by the browser.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Hitachi ABB Power Grids reports this vulnerability affects the following product:
- eSOMS: All Versions 6.3 and prior
## 3.2
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-07-14
Published