CVE-2021-40338
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/01/2022
Last modified:
09/08/2022
Description
Hitachi Energy LinkOne product, has a vulnerability due to a web server misconfiguration, that enables debug mode and reveals the full path of the filesystem directory when an attacker generates errors during a query operation. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23; 3.24; 3.25; 3.26.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:hitachi:linkone:3.20:*:*:*:*:*:*:* | ||
| cpe:2.3:a:hitachi:linkone:3.22:*:*:*:*:*:*:* | ||
| cpe:2.3:a:hitachi:linkone:3.23:*:*:*:*:*:*:* | ||
| cpe:2.3:a:hitachi:linkone:3.24:*:*:*:*:*:*:* | ||
| cpe:2.3:a:hitachi:linkone:3.25:*:*:*:*:*:*:* | ||
| cpe:2.3:a:hitachi:linkone:3.26:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



