{
    "CVE_data_meta": {
        "ASSIGNER": "cybersecurity@hitachienergy.com",
        "DATE_PUBLIC": "2021-12-23T17:00:00.000Z",
        "ID": "CVE-2021-40337",
        "STATE": "PUBLIC",
        "TITLE": "OWASP Related Vulnerabilities in Hitachi  Energy\u2019s LinkOne Product"
    },
    "affects": {
        "vendor": {
            "vendor_data": [
                {
                    "product": {
                        "product_data": [
                            {
                                "product_name": "LinkOne",
                                "version": {
                                    "version_data": [
                                        {
                                            "version_affected": "=",
                                            "version_name": "3.20",
                                            "version_value": "3.20"
                                        },
                                        {
                                            "version_affected": "=",
                                            "version_name": "3.22",
                                            "version_value": "3.22"
                                        },
                                        {
                                            "version_affected": "=",
                                            "version_name": "3.23",
                                            "version_value": "3.23"
                                        },
                                        {
                                            "version_affected": "=",
                                            "version_name": "3.24",
                                            "version_value": "3.24"
                                        },
                                        {
                                            "version_affected": "=",
                                            "version_name": "3.25",
                                            "version_value": "3.25"
                                        },
                                        {
                                            "version_affected": "=",
                                            "version_name": "3.26",
                                            "version_value": "3.26"
                                        }
                                    ]
                                }
                            }
                        ]
                    },
                    "vendor_name": "Hitachi Energy"
                }
            ]
        }
    },
    "credit": [
        {
            "lang": "eng",
            "value": "Hitachi Energy thanks the following for working with us to help protect our customers:  Compa\u00f1\u00eda Minera Do\u00f1a In\u00e9s de Collahuasi SCM."
        }
    ],
    "data_format": "MITRE",
    "data_type": "CVE",
    "data_version": "4.0",
    "description": {
        "description_data": [
            {
                "lang": "eng",
                "value": "Cross-site Scripting (XSS) vulnerability in Hitachi Energy LinkOne allows an attacker that manages to exploit the vulnerability can take advantage to exploit multiple web attacks and stole sensitive information. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23; 3.24; 3.25; 3.26."
            }
        ]
    },
    "generator": {
        "engine": "Vulnogram 0.0.9"
    },
    "impact": {
        "cvss": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.2,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
        }
    },
    "problemtype": {
        "problemtype_data": [
            {
                "description": [
                    {
                        "lang": "eng",
                        "value": "CWE-79 Cross-site Scripting (XSS)"
                    }
                ]
            }
        ]
    },
    "references": {
        "reference_data": [
            {
                "name": "https://search.abb.com/library/Download.aspx?DocumentID=8DBD000079&LanguageCode=en&DocumentPartId=&Action=Launch",
                "refsource": "CONFIRM",
                "url": "https://search.abb.com/library/Download.aspx?DocumentID=8DBD000079&LanguageCode=en&DocumentPartId=&Action=Launch"
            }
        ]
    },
    "solution": [
        {
            "lang": "eng",
            "value": "For each version, apply the available patch or update to version 3.27. "
        }
    ],
    "source": {
        "discovery": "USER"
    }
}