Lucene search

K
cveHitachi EnergyCVE-2023-2621
HistoryNov 01, 2023 - 3:15 a.m.

CVE-2023-2621

2023-11-0103:15:07
CWE-22
Hitachi Energy
web.nvd.nist.gov
31
mcfeeder
ssw package
vulnerability
arbitrary file write
cve-2023-2621
nvd
security

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

16.2%

The McFeeder server (distributed as part of SSW package), is susceptible to an arbitrary file write vulnerability on the MAIN computer
system. This vulnerability stems from the use of an outdated version of a third-party library, which is used to extract archives uploaded to McFeeder server. An authenticated malicious client can
exploit this vulnerability by uploading a crafted ZIP archive via the
network to McFeeder’s service endpoint.

Affected configurations

Nvd
Node
hitachienergymodular_advanced_control_for_hvdcRange5.0–7.17.0.0
VendorProductVersionCPE
hitachienergymodular_advanced_control_for_hvdc*cpe:2.3:a:hitachienergy:modular_advanced_control_for_hvdc:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "MACH System Software",
    "vendor": "Hitachi Energy",
    "versions": [
      {
        "lessThan": "7.17.0.0",
        "status": "affected",
        "version": "5.0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

16.2%

Related for CVE-2023-2621