PatchSiren cyber security CVE debrief
CVE-2021-35534 Hitachi Energy CVE debrief
CVE-2021-35534 is an industrial-control vulnerability in Hitachi Energy Relion 670/650/SAM600-IO products. CISA and the vendor describe a database-schema weakness that can be abused after an attacker already has valid account credentials or a session ticket. Through the configuration tool using the proprietary ODBC protocol on TCP 2102, an attacker may manipulate database tables for privilege escalation, leading to unauthorized modification or permanent device disabling. The issue was publicly disclosed on 2021-11-04 and later updated in the advisory record, with the latest source revision dated 2025-02-25.
- Vendor
- Hitachi Energy
- Product
- Relion 670 series
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2021-12-09
- Original CVE updated
- 2021-12-09
- Advisory published
- 2021-12-09
- Advisory updated
- 2021-12-09
Who should care
OT and ICS operators using Hitachi Energy Relion 670 or 650 series, SAM600-IO deployments, and teams responsible for protection relays, substation automation, and configuration management should prioritize this advisory. Security teams should also care if any maintenance workflow exposes the configuration tool or TCP 2102 to broader-than-necessary access.
Technical summary
The advisory says the flaw is in the product’s internal database schema. Exploitation requires prior access to valid credentials for any account or a session ticket for an account. Once authenticated, an attacker can use the configuration tool over proprietary ODBC on TCP 2102 to manipulate database tables and escalate privileges. The reported impact is unauthorized modification or permanent disabling of the device. The advisory includes vendor fixes for multiple product/version branches, including Relion 670 series, Relion 650 series, and Relion SAM600-IO.
Defensive priority
High. The vulnerability affects operational technology devices and can result in device disablement or unauthorized changes, but it requires valid account access first. That makes access control hardening and timely patching the immediate priorities.
Recommended defensive actions
- Update affected systems to the vendor-fixed versions listed in the advisory, including Relion 670/650/SAM600-IO 2.2.1.8, Relion 670 2.2.2.5, Relion 670 2.2.3.5, Relion 670/650 2.2.4.3, Relion 670/650/SAM600-IO 2.2.5.2, 2
- Confirm which exact product family and revision is deployed before scheduling remediation, since affected and fixed versions vary by branch.
- Restrict and monitor access to the configuration tool and the TCP 2102 ODBC service so only authorized maintenance systems and users can reach it.
- Protect account credentials and session tickets with strong access control, least privilege, and secure handling of remote or shared maintenance workflows.
- Use CISA’s industrial-control security guidance and defense-in-depth practices to segment OT assets and limit management-plane exposure.
- Validate that no unauthorized configuration changes or unexpected device disablement events have occurred on exposed relays and related systems.
Evidence notes
All substantive claims are taken from the supplied CISA CSAF advisory content and the referenced vendor/CISA links. The advisory states that exploitation requires prior credential or session-ticket access and that the configuration tool uses proprietary ODBC over TCP 2102. The supplied source also lists affected product families, version-specific remediations, and no KEV designation.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-35534 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-35534
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-35534 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-35534
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-065-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-065-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.