Backup file without encryption vulnerability is found in Hitachi ABB Power Grids System Data Manager – SDM600 allows attacker to gain access to sensitive information. This issue affects: Hitachi ABB Power Grids System Data Manager – SDM600 1.2 versions prior to FP2 HF6 (Build Nr. 1.2.14002.257).
Solution:
Workaround:
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.