• Services
    • Assess
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Transform
      • SOC Consultancy
      •     SOC Maturity Assessment
      •     SOC Model Evaluation
      •     SOC Gap Analysis
      •     SIEM Gap Analysis
      •     SIEM Optimization
      •     SOC Content Pack
    • Train
      • Security Awareness and Training
      • Tabletop Exercise
      • Simulated Cyber Attack Exercises
    • Respond
      • Incident Response
      • Incident Analysis
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Press Release
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
Rewterz Threat Alert – Dridex Banking Trojan – Active IOCs
December 13, 2021
Rewterz Threat Advisory – CVE-2021-4104 – Apache Log4j Vulnerability
December 14, 2021

Rewterz Threat Advisory – ICS: Hitachi Energy GMS600, PWC600, and Relion

December 13, 2021

Severity

High

Analysis Summary

CVE-2021-35534

An attacker could exploit this vulnerability by first gaining access to credentials of any account or have access to a session ticket issued for an account. After gaining access via the configuration tool that accesses the proprietary Open Database Connectivity (ODBC) protocol (TCP 2102), the database table can be manipulated for privilege escalation, which then allows unauthorized modification or permanent disabling of the device.

Impact

  • Security Bypass

Affected Vendors

  • Hitachi Energy

Affected Products

  • GMS600: Version 1.2.0
  • GMS600: Version 1.3.0
  • GMS600: Version 1.3.1.0
  • PWC600: Version 1.1.0.0
  • PWC600: Version 1.1.0.1
  • PWC600: Version 1.0.1.0
  • PWC600: Version 1.0.1.1
  • PWC600: Version 1.0.1.3
  • PWC600: Version 1.0.1.4
  • Relion 670/650 series: Version 2.2.0 all revisions
  • Relion 670/650/SAM600-IO series: Version 2.2.1 all revisions
  • Relion 670 series: Version 2.2.2 all revisions
  • Relion 670 series: Version 2.2.3 revisions up to 2.2.3.4
  • Relion 670/650 series: Version 2.2.4 all revisions
  • Relion 670/650/SAM600-IO series: Version 2.2.5 revisions up to 2.2.5.1
  • Relion 670/650 series: Version 2.1 all revisions
  • Relion 670 series: Version 2.0 all revisions
  • Relion 650 series: Version 1.3 all revisions
  • Relion 650 series: Version 1.2 all revisions
  • Relion 650 series: Version 1.1 all revisions
  • Relion 650 series: Version 1.0 all revisions

Remediation

Refer to CISA Advisory for the patch, upgrade, or suggested workaround information.

https://www.cisa.gov/uscert/ics/advisories/icsa-21-343-01
  • Services
    • Assess
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Respond
      • Incident Response
      • Incident Analysis
  • Transform
    • SOC Consultancy
    •     SOC Maturity Assessment
    •     SOC Model Evaluation
    •     SOC Gap Analysis
    •     SIEM Gap Analysis
    •     SIEM Optimization
    •     SOC Content Pack
  • Train
    • Security Awareness and Training
    • Tabletop Exercise
    • Simulated Cyber Attack Exercises
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
COPYRIGHT © REWTERZ. ALL RIGHTS RESERVED.