关键信息摘要 受影响的产品和厂商信息 Vendor: Hitachi ABB Power Grids Product: Ellipse EAM Affected Versions: Ellipse EAM versions prior to and including 9.0.25 Critical Infrastructure Sectors: Energy Sector Countries/Areas Deployed: Worldwide 漏洞概述 Vulnerabilities: - Cross-Site Scripting (CWE-79): - CVE: CVE-2021-27416 - CVSS v3 Score: 5.5 - Risk: Exploitable remotely; low skill level to exploit - Impact: Compromise of confidential information or takeover of the user’s session. - User Interface Misrepresentation of Critical Information (CWE-451): - CVE: CVE-2021-27414 - CVSS v3 Score: 5.5 - Risk: Exploitable remotely; low skill level to exploit - Impact: Gathering of authentication credentials by tricking a user into visiting a malicious website posing as a login page for the Ellipse application. 建议的缓解措施 Hitachi ABB Power Grids推荐的安全实践: - 升级到Ellipse EAM Version 9.0.23或更高版本。 - 遵循最佳安全实践和防火墙配置。 - 实施物理保护和网络隔离。 - 限制对外开放的端口。 - 控制关键系统用于互联网活动。 - 确保便携式设备和可移除存储介质的病毒扫描。 - 加强安全意识培训。